Trojan

Trojan.Dropper.PE4 removal guide

Malware Removal

The Trojan.Dropper.PE4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.PE4 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

TRANSERSDATAFORME.COM

How to determine Trojan.Dropper.PE4?


File Info:

crc32: 0E3753EC
md5: 04318c294c8f36a9d01b9577e5aa203d
name: 04318C294C8F36A9D01B9577E5AA203D.mlw
sha1: ce6950e8a784983dd8babb349d444ab005c107a9
sha256: 525a23c25330c5dd2b6ed6649bff4fbe978c506d5caec172cd295afd10346587
sha512: 5a1e3d6c4cf39905a0305bc150ef9be62ada552ee3ffeefe8c97216cd203252845ae5af57e75fa98a1ab2809cba38eb5b48e5b6b33c2804e92c37e44a5f0873a
ssdeep: 3072:/0IHEOxS777YJY85zGw3CJCA96vklQo9:/LkN8JZTSJJkvkKo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Dropper.PE4 also known as:

BkavW32.PolymorphicMalwareNNB.Fam.Trojan
K7AntiVirusBackdoor ( 003210941 )
LionicTrojan.Win32.Gbot.lszJ
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Multi.363
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaBackdoor.Gbot.Win32.8002
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:Win32/Kryptik.411bb71f
K7GWBackdoor ( 003210941 )
Cybereasonmalicious.94c8f3
CyrenW32/Goolbot.P.gen!Eldorado
SymantecBackdoor.Cycbot!gen10
ESET-NOD32a variant of Win32/Kryptik.AJSE
APEXMalicious
AvastWin32:Cycbot-PY [Trj]
KasperskyBackdoor.Win32.Gbot.qwk
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.Gbot.hvcvf
MicroWorld-eScanGen:Heur.Conjar.9
TencentWin32.Backdoor.Gbot.Cqz
Ad-AwareGen:Heur.Conjar.9
ComodoTrojWare.Win32.Kryptik.YAK@4lrbdg
BitDefenderThetaGen:NN.ZexaF.34266.gqW@a0nl!hei
VIPREBackdoor.Win32.Cycbot.ga (v)
TrendMicroBKDR_CYCBOT.SMEE
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nc
FireEyeGeneric.mg.04318c294c8f36a9
EmsisoftGen:Heur.Conjar.9 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Gbot.oov
WebrootW32.Cycbot.Gen
AviraBDS/GBot.qwkan
Antiy-AVLTrojan/Generic.ASMalwS.BF3A9
KingsoftWin32.Hack.Gbot.(kcloud)
MicrosoftPWS:Win32/Fareit.AJ!bit
ArcabitTrojan.Conjar.9
SUPERAntiSpywareTrojan.Agent/Gen-Kazy[Ex]
GDataGen:Heur.Conjar.9
TACHYONBackdoor/W32.GBot.101376.B
AhnLab-V3Backdoor/Win32.Gbot.R18759
Acronissuspicious
McAfeeBackDoor-EXI.gen.aa
MAXmalware (ai score=100)
VBA32Trojan.FakeAV.0997
MalwarebytesTrojan.Dropper.PE4
PandaTrj/Cycbot.gen
TrendMicro-HouseCallBKDR_CYCBOT.SMEE
RisingTrojan.Generic@ML.92 (RDML:s58nWd4o1Z9IZs9plu9MzA)
YandexTrojan.GenAsa!UPG0nsYnFpo
IkarusBackdoor.Win32.Agent
FortinetW32/Kryptik.ACO!tr
AVGWin32:Cycbot-PY [Trj]
Paloaltogeneric.ml

How to remove Trojan.Dropper.PE4?

Trojan.Dropper.PE4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment