Malware

Dropper.6 removal tips

Malware Removal

The Dropper.6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropper.6 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Dropper.6?


File Info:

crc32: B1B784DF
md5: bfcbe70c6e96909a5b435a71e8a09ef2
name: BFCBE70C6E96909A5B435A71E8A09EF2.mlw
sha1: 1ff1c2ed7e2056b7aca00d1ecf21216fe619cbd6
sha256: e96beeedd29afa555ba129d3ce9e86164faaf12eb5b4d12929bfd63712c3dc67
sha512: 38069ff58f1399f85c7d9e986ef9fe22328b58ed928a378c5d38b2b606235c1aac382ae7dd40498f1f02d33f499eb5373d10b276806ce1472189b24f1f1e4580
ssdeep: 3072:O/NMOW9j78XmZ3B+Vc9MpiZS0gj79qX8GBKaZBvXtGWw0/:4mOfKMVcGsZSZj5kvBFntBP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Artem Izmaylov
FileVersion: 3.0.0.810
CompanyName: AIMP DevTeam
Comments: Made in Russia
ProductName: AIMP3
FileDescription: AIMP3
Translation: 0x0419 0x04e3

Dropper.6 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3f61 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.FakeAV.11616
CynetMalicious (score: 100)
ALYacGen:Variant.Dropper.6
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.11551
SangforTrojan.Win32.Save.a
K7GWSpyware ( 0055e3f61 )
Cybereasonmalicious.c6e969
ESET-NOD32Win32/TrojanClicker.VB.ODU
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ClamAVWin.Dropper.Trickbot-9866144-0
KasperskyTrojan-Ransom.Win32.Blocker.cobc
BitDefenderGen:Variant.Dropper.6
NANO-AntivirusTrojan.Win32.Blocker.cqkguz
MicroWorld-eScanGen:Variant.Dropper.6
TencentWin32.Trojan.Blocker.Pkrb
Ad-AwareGen:Variant.Dropper.6
SophosML/PE-A + Mal/Trickbot-E
ComodoMalware@#25cse07dihj7n
BitDefenderThetaGen:NN.ZevbaF.34050.im0@aSGBeMmk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.11JQ15
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
FireEyeGeneric.mg.bfcbe70c6e96909a
EmsisoftGen:Variant.Dropper.6 (B)
SentinelOneStatic AI – Suspicious PE
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.50A994
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/VBInject
ArcabitTrojan.Dropper.6
GDataGen:Variant.Dropper.6
AhnLab-V3Trojan/Win32.Blocker.C1127884
McAfeeGeneric.emw
MAXmalware (ai score=84)
VBA32Hoax.Blocker
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SPNR.11JQ15
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.COBC!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HykCEpsA

How to remove Dropper.6?

Dropper.6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment