Trojan

Trojan.Dropper (A) removal guide

Malware Removal

The Trojan.Dropper (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper (A) virus can do?

  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r5—sn-4g5edne7.gvt1.com

How to determine Trojan.Dropper (A)?


File Info:

crc32: 58BB6E5D
md5: 78e4785ce2b3ac8f267b972a4fe4156d
name: setup_c.exe
sha1: ec045175df0f1042b459f01d161037388c602a5f
sha256: 471396b8ffc81bf03cdc5677859b134bc6b3ec88d43dd46cde50d75da64b0686
sha512: b0b92f5d20b8a3bd1c55d0f5b3a59810e9df2487f3b6226a6c32becec3b21171ec55de0b10ace05d33afb357b150540910912d1727a6edeaf7012fb3616a45a6
ssdeep: 49152:L9PJQvrJQmuio39Cm3yLLw4sjrMZsIm3pBgq5O:L9xQvrSmXo3UbLlsP7p55
type: MS-DOS executable, MZ for MS-DOS

Version Info:

InternalName: mfpmp.exe
FileDescription: Norwegian Keyboard Layout
OriginalFilename: mfpmp.exe
Comments: sbZUFiNiHHPeNqln73oFt9pcuTcqc8uN26c6gTVsDH95NUVrx9SP6wuITXDGDR2ho1iU1P
CompanyName: Windows System Profile SystemId DLL
Translation: 0x0809 0x04b0

Trojan.Dropper (A) also known as:

FireEyeGeneric.mg.78e4785ce2b3ac8f
McAfeeArtemis!78E4785CE2B3
MalwarebytesTrojan.Qulab
AegisLabRiskware.Win32.Generic.1!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.33558.8nuaamwQJ!li
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Trojan.QuilMiner.A2M9LS
KasperskyUDS:DangerousObject.Multi.Generic
DrWebTrojan.Siggen9.1594
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.moderate.ml.score
CMCVirus.Win32.Sality!O
EmsisoftTrojan.Dropper (A)
IkarusTrojan.Win32.Autoit
JiangminRiskTool.Miner.fl
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_66%
FortinetAutoIt/Packed.KY!tr
Paloaltogeneric.ml

How to remove Trojan.Dropper (A)?

Trojan.Dropper (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment