Trojan

MSIL/TrojanDropper.Binder.DX (file analysis)

Malware Removal

The MSIL/TrojanDropper.Binder.DX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDropper.Binder.DX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • A wscript.exe process commonly used in script or document file downloaders initiated network activity

How to determine MSIL/TrojanDropper.Binder.DX?


File Info:

crc32: 03D71E83
md5: 06022f3cd8419a61ab2b1bb7e17a6cc8
name: 06022F3CD8419A61AB2B1BB7E17A6CC8.mlw
sha1: 76891e11c0721e2bba4eaec16f445be23ee21e90
sha256: 1dc8217fcc0647c66349992e2a4905d051145ca1e5c5e97f86f2813c79f00b6f
sha512: a2d44e171c5981a672b17b9cf7d852dd9040488242db80f78132562c725b9cee4d2e8caa24b89265359bf47aa0f0fd3d404413cab768759d6eb186cc40c9ebe9
ssdeep: 6144:Kq8jedR33rdS6acnmHYLbJUHtrlTdrzfeD2YNlw40j8di:KdSdRrEGmHYLNElTdrzs2YHw40r
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: trfr.Scr
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: trfr.Scr

MSIL/TrojanDropper.Binder.DX also known as:

K7AntiVirusTrojan ( 004b993f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Generic.Win32.296388
SangforTrojan.MSIL.AgentTesla.KM
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:MSIL/Bladabindi.68f4e989
K7GWTrojan ( 004b993f1 )
Cybereasonmalicious.cd8419
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Binder.DX
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Binder.fghhkx
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
TencentWin32.Trojan.Generic.Che
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-S
ComodoMalware@#2jo4czn0i6au0
BitDefenderThetaAI:Packer.8014781225
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.06022f3cd8419a61
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2742A5E
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Heur.MSIL.Bladabindi.1
AhnLab-V3Trojan/Win32.MSIL.C2687635
McAfeeArtemis!06022F3CD841
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
YandexTrojan.Agent!SKOEmi1fUAM
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Dropper_Binder.BFP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSIL/TrojanDropper.Binder.DX?

MSIL/TrojanDropper.Binder.DX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment