Trojan

Trojan-Dropper.Win32.Dropback.ld removal tips

Malware Removal

The Trojan-Dropper.Win32.Dropback.ld is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Dropback.ld virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-Dropper.Win32.Dropback.ld?


File Info:

crc32: DA476EA6
md5: 838f727fcc9e340c3c1831ae461f5acd
name: winlog.exe
sha1: 7d8af135656fd29b8806d1982b6ed2aba86f56d7
sha256: 9ed5eeffd9f937a6da2a7e6546bdeb3df216d5857b17d2eb320132db8e298ffc
sha512: 0e5ccbbfef50420f6bc226b651863f77952e12143f3a4dd33741e3b170e40e31780b8bee36f352e0bcba51c99889abc7acd2aab77a67162af1444e22b85f5ed0
ssdeep: 24576:sLK+I+HnvHcjoE6uJxZvRJrbd/znfZJfmn1HK8k1zQl:9+H/cj8uJxZvRJrbd/znfZJfmpKtY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2007-2015 Shark Labs
InternalName: Below Deductive
FileVersion: 4.3.2.12
CompanyName: Shark Labs
PrivateBuild: 4.3.2.12
LegalTrademarks: (C) 2007-2015 Shark Labs
Comments: Roaming Woolworths Physical Review Zombie
ProductName: Below Deductive
Languages: English
ProductVersion: 4.3.2.12
FileDescription: Roaming Woolworths Physical Review Zombie
OriginalFilename: Below Deductive
Translation: 0x0409 0x04b0

Trojan-Dropper.Win32.Dropback.ld also known as:

MicroWorld-eScanTrojan.GenericKD.33566758
Qihoo-360Generic/Trojan.231
McAfeeArtemis!838F727FCC9E
MalwarebytesSpyware.FormBook
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.33566758
K7GWTrojan ( 005635c61 )
K7AntiVirusTrojan ( 005635c61 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HCGK
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Dropback.ld
AlibabaTrojanDropper:Win32/Dropback.ccc80cb6
RisingDropper.Dropback!8.11750 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33566758 (B)
F-SecureTrojan.TR/AD.Sagonaire.gcc
DrWebTrojan.Siggen9.26110
TrendMicroTROJ_GEN.R03BC0DCS20
McAfee-GW-EditionRDN/Generic Dropper
FortinetW32/GenKryptik.EGZN!tr
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.FLHZ-5138
JiangminTrojanDropper.Dropback.bp
WebrootW32.Malware.Gen
AviraTR/AD.Sagonaire.gcc
MAXmalware (ai score=100)
ArcabitTrojan.Generic.D2003026
ZoneAlarmTrojan-Dropper.Win32.Dropback.ld
MicrosoftTrojan:Win32/Occamy.C
ALYacTrojan.Agent.FormBook
Ad-AwareTrojan.GenericKD.33566758
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DCS20
TencentWin32.Trojan-dropper.Dropback.Dztv
GDataTrojan.GenericKD.33566758
BitDefenderThetaGen:NN.ZexaF.34104.Zy0@a435Wqki
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan-Dropper.Win32.Dropback.ld?

Trojan-Dropper.Win32.Dropback.ld removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment