Malware

Dropper.96 information

Malware Removal

The Dropper.96 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropper.96 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Dropper.96?


File Info:

name: 862087ED0C94C58B162E.mlw
path: /opt/CAPEv2/storage/binaries/dadbfd66c6f0724d987eaf714c95e246aefe7efd7d0bd5ebff5cb598cfe4573b
crc32: B2F86B9F
md5: 862087ed0c94c58b162e4ac02eab2c38
sha1: 11d513baa7018549f3f505c6a83e494ea9796751
sha256: dadbfd66c6f0724d987eaf714c95e246aefe7efd7d0bd5ebff5cb598cfe4573b
sha512: 8225674ee682ec36f6b40c0bad410ba7efb6353e6930c16c56eabda2866bdd3b8ab9d09353d0b90d356fa7948ec09d12949ce9480e4343c68e7500ec0def8c98
ssdeep: 6144:QzmcxCnTQWI+6sDVTJEP/OHHbSG9DsWqC6VctkdZhWH+mzM2w+QKJ6wzPUicrc1+:KCTQx+VJHGYqVOtBeCqOb26NmLHE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C794125B2F65B48CD7B8AA7DCAF36630C534361949FB8ED71CE0B40528F0522B92786D
sha3_384: 962f9852b1cd994d34e5a320449366c0e34d1dc7d772c9643ec9e7218e311bd9047bf1911e1e821c782f2d0f74fff69e
ep_bytes: eba489c05589e5000000000000000000
timestamp: 2005-04-18 06:29:12

Version Info:

Comments:
CompanyName: MSFT Corp
FileDescrsiption: calc.exe
FileVersion: 2.1.1.2
InternalName: calc.exe
LegalCopyright: Copyright (C) 2011
LegalTrademarks:
OriginalFilename: calc.exe
PrivateBuild:
ProductName: Calc
ProductVersion: 3.1.1.3
SpecialBuild:
Translation: 0x0800 0x0025

Dropper.96 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.4379
MicroWorld-eScanGen:Variant.Dropper.96
FireEyeGeneric.mg.862087ed0c94c58b
McAfeeDownloader-FVD!862087ED0C94
CylanceUnsafe
VIPREGen:Variant.Dropper.96
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.d0c94c
ArcabitTrojan.Dropper.96
BitDefenderThetaGen:NN.ZexaF.34806.Au0@auDW1Hm
VirITTrojan.Win32.Inject2.DKU
CyrenW32/S-f618805c!Eldorado
SymantecTrojan.Zbot!gen65
ESET-NOD32Win32/Spy.Zbot.AAU
ClamAVWin.Dropper.Zbot-9957449-0
KasperskyTrojan-Spy.Win32.Zbot.zgpc
BitDefenderGen:Variant.Dropper.96
NANO-AntivirusTrojan.Win32.Inject.cmmmvd
SUPERAntiSpywareTrojan.Agent/Gen-BASY
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10c85c13
Ad-AwareGen:Variant.Dropper.96
SophosML/PE-A + Mal/Ransom-BY
ComodoTrojWare.Win32.Spy.Zbot.ADCX@542jmg
ZillyaTrojan.Inject.Win32.63900
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Dropper.96 (B)
IkarusTrojan.Injector
JiangminTrojanDownloader.Agent.ekoz
AviraTR/Yarwi.B.15
Antiy-AVLTrojan/Generic.ASMalwS.77
MicrosoftPWS:Win32/Zbot!GO
ViRobotDropper.Agent.441856.A
GDataWin32.Trojan.PSE1.1GJTALU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R86809
VBA32TrojanSpy.Zbot
ALYacGen:Variant.Dropper.96
TACHYONTrojan/W32.Inject.441856.D
MalwarebytesBackdoor.Bot
APEXMalicious
RisingTrojan.Generic@AI.91 (RDML:7DAXOTjWcft/M+73vD20Eg)
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.6623332.susgen
FortinetW32/Small.AAB!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Dropper.96?

Dropper.96 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment