Malware

How to remove “Troj/Mdrop-JTO”?

Malware Removal

The Troj/Mdrop-JTO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Mdrop-JTO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Troj/Mdrop-JTO?


File Info:

name: 631A5AC38A6035B76565.mlw
path: /opt/CAPEv2/storage/binaries/8c4f686e60236b89092394c07cb2a07c98f85db20a33095731a33fae8804b06f
crc32: 5EB5CAAE
md5: 631a5ac38a6035b765651dbce2d57fdc
sha1: d692669f3f49853e6b1c99b4462f604bd4768d5f
sha256: 8c4f686e60236b89092394c07cb2a07c98f85db20a33095731a33fae8804b06f
sha512: bb2eda13f1735d15897c76e714d6f61d7fbc36fcd79e035992f72b006d3f765cd5bdf18603d12107c219e65daabd3900b2118a26dee88896dc5cbc0f52da5e3d
ssdeep: 24576:vafDWMm8PeUHOmKBUMDqKihLZm91qUZmwZE:vafxPR6D7uZmn1ZmwZE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D615E142F98041F4C4D56A764CB956020AB6BE9781E5FE5761C87B023833D21E73AEFE
sha3_384: c0541b8d887e01e10d78de3396f2d2c1dd00df57e7e9b2e6aab57e55121790c88e8bee7f5d7c3d9e4615e3ad349ab5f6
ep_bytes: e8ff190000e97ffeffff3b0da0404100
timestamp: 2016-11-05 04:20:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Word
FileVersion: 14.0.6024.1000
InternalName: WinWord
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.6024.1000
Translation: 0x0000 0x04e4

Troj/Mdrop-JTO also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98267
FireEyeGeneric.mg.631a5ac38a6035b7
SkyhighBehavesLike.Win32.Generic.dc
ALYacTrojan.GenericKDZ.98267
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.3757901
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005490181 )
K7GWTrojan ( 005490181 )
Cybereasonmalicious.f3f498
ArcabitTrojan.Generic.D17FDB
BitDefenderThetaGen:NN.ZexaF.36792.442@ay72oJhi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RTY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Facido-9768987-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.98267
NANO-AntivirusTrojan.Win32.Fakealert.fhnukn
AvastWin32:DropperX-gen [Drp]
RisingDropper.Agent!1.B38C (CLASSIC)
SophosTroj/Mdrop-JTO
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Fakealert.58572
VIPRETrojan.GenericKDZ.98267
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.98267 (B)
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Generic.hrsto
VaristW32/FakeAlert.AEG.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan[Dropper]/Win32.Facido
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDropper.Facido.A@7d50kc
MicrosoftTrojanDropper:Win32/Facido.A!bit
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.18RDAY1
GoogleDetected
AhnLab-V3Dropper/Win.FC.R620036
Acronissuspicious
McAfeeGenericRXMT-FC!631A5AC38A60
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Agent.hct
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.RTY!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Mdrop-JTO?

Troj/Mdrop-JTO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment