Trojan

Trojan.Dropper.Python removal

Malware Removal

The Trojan.Dropper.Python is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.Python virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • CAPE detected the PyInstaller malware family

Related domains:

wpad.local-net

How to determine Trojan.Dropper.Python?


File Info:

name: 5A657EAB48EDA248452E.mlw
path: /opt/CAPEv2/storage/binaries/e81f251b6d80d16f4eb37520000a7fe34258473727076caaaa6a90618779e8d8
crc32: 30AB7809
md5: 5a657eab48eda248452ec6708a277d27
sha1: c08a6a922c73bcc86c4a59b6ff899a4e853d098b
sha256: e81f251b6d80d16f4eb37520000a7fe34258473727076caaaa6a90618779e8d8
sha512: 8bcac26009978378efec0c62356245a27a2082b12479b4aa6c25413307802b939e61e94eb51f74bc347fc5a8494ecdc813c2609c3aeb6feddcf75cc125324046
ssdeep: 196608:CuxnN3ICteEroXx9VfEqlbkkwR7VTEJZFmv3g4+IeU:P3InEroXxfEqirRRoJZYPP+x
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1C5763308A3941DECF1B60035EAA04925D176B4334744D98B6B2C92278FE7EE5ADB7FC4
sha3_384: c4f727edbb6f226acd808e647d8e29139e81e7962ed02a0b0c84587329c1e7686e05ecfd328a5eaccf043316d70e28c0
ep_bytes: 4883ec28e8f70400004883c428e97afe
timestamp: 2021-08-01 04:39:46

Version Info:

0: [No Data]

Trojan.Dropper.Python also known as:

LionicTrojan.Python.Disco.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38093407
FireEyeTrojan.GenericKD.38093407
ALYacTrojan.GenericKD.38093407
MalwarebytesTrojan.Dropper.Python
K7AntiVirusTrojan ( 00573cac1 )
AlibabaTrojanPSW:Win32/Almi_Disco.m
K7GWTrojan ( 00573cac1 )
CyrenPYC/Disgrab.A.gen!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.EP
APEXMalicious
KasperskyUDS:Trojan-PSW.Win32.Disco
BitDefenderTrojan.GenericKD.38093407
AvastFileRepMalware
TencentWin32.Trojan-psw.Agent.Swuv
Ad-AwareTrojan.GenericKD.38093407
SophosMal/Generic-S
DrWebPython.Stealer.234
ZillyaTrojan.Disco.Win32.1337
TrendMicroTROJ_GEN.R002C0PKM21
McAfee-GW-EditionBehavesLike.Win64.Ransom.vc
EmsisoftTrojan.GenericKD.38093407 (B)
GDataWin32.Trojan-Stealer.Cordimik.HKVOT6
AviraHEUR/AGEN.1145661
Antiy-AVLTrojan/Generic.ASMalwS.34493BB
GridinsoftRansom.Win64.Sabsik.sa
ViRobotTrojan.Win32.Z.Disco.7148407
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWS.R441911
McAfeeArtemis!5A657EAB48ED
MAXmalware (ai score=85)
VBA32TrojanPSW.Python
TrendMicro-HouseCallTROJ_GEN.R002C0PKM21
FortinetPython/Disco.BC67!tr.pws
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Dropper.Python?

Trojan.Dropper.Python removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment