Malware

Should I remove “Generic.Addrop.A.9DFFD546 (B)”?

Malware Removal

The Generic.Addrop.A.9DFFD546 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Addrop.A.9DFFD546 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Installs a browser addon or extension
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Collects information to fingerprint the system

How to determine Generic.Addrop.A.9DFFD546 (B)?


File Info:

name: 54FA9AB1BD291B5BD406.mlw
path: /opt/CAPEv2/storage/binaries/9311ebdcd2ee41da9486f0f5f54f0772edca71d8c675e541d98f0d875c8905b2
crc32: 40AC43FC
md5: 54fa9ab1bd291b5bd40638379be68b06
sha1: 5be91e61134f876af83ccf0250c35db6f809ded8
sha256: 9311ebdcd2ee41da9486f0f5f54f0772edca71d8c675e541d98f0d875c8905b2
sha512: 489284b332b3b9eb1ed0dbee06a9e8b7201c8b3d65806009e033bda8a6707c6af8a61d15d41d34533ce956bf2b5930fada67c909b5a80237fef59731f437c0ca
ssdeep: 12288:uaHc64b888888888888W88888888888IxscV7TdjL47zdU5imYC45733rD+zG/o1:F86ZiW7uvmQSEzezG/aYFkJR30F6rp86
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13FF41213B3C30071F5214A358C6680049D677DBD19F460AA2FFDEA4E4BBA7C69C76B62
sha3_384: 36600fa42501c65848916c06cb3485f5e2984111b730277f05efaaf18851002991ed2e967bc78dcde2dee2bf417beca0
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion: 122.192
LegalCopyright:
ProductName:
ProductVersion: 122.192
Translation: 0x0000 0x04b0

Generic.Addrop.A.9DFFD546 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Addrop.A.9DFFD546
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Addrop.D.gen!Eldorado
ESET-NOD32a variant of Win32/TrojanDropper.Addrop.CH
ClamAVWin.Packed.Agentino-9874843-0
KasperskyHEUR:Trojan-Dropper.Win32.Agentino.gen
BitDefenderGeneric.Addrop.A.9DFFD546
CynetMalicious (score: 100)
APEXMalicious
RisingDownloader.TaskLoader/ARCHIVE!1.CDEA (CLASSIC)
EmsisoftGeneric.Addrop.A.9DFFD546 (B)
DrWebAdware.OxyPumper.18
VIPREGeneric.Addrop.A.9DFFD546
McAfee-GW-EditionBehavesLike.Win32.FileTour.bc
FireEyeGeneric.Addrop.A.9DFFD546
SophosGeneric ML PUA (PUA)
IkarusTrojan-Dropper.Addrop
JiangminTrojanDropper.Agentino.a
AviraTR/Crypt.XPACK.Gen8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agentino.gen
GDataGeneric.Addrop.A.9DFFD546
AhnLab-V3Trojan/Win.Addrop.C5287194
Acronissuspicious
ALYacGeneric.Addrop.A.9DFFD546
MalwarebytesMalware.AI.2298992223
AvastOther:Malware-gen [Trj]
TencentTrojan.Win32.Addrop.xa
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Addrop.CH!tr
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.1134f8

How to remove Generic.Addrop.A.9DFFD546 (B)?

Generic.Addrop.A.9DFFD546 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment