Trojan

Trojan-Dropper.Win32.Scrop.aczv malicious file

Malware Removal

The Trojan-Dropper.Win32.Scrop.aczv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Scrop.aczv virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine Trojan-Dropper.Win32.Scrop.aczv?


File Info:

crc32: 358DE736
md5: 911864e5dfb40e18f219be9ea6293d08
name: tmpwayvwoq4
sha1: 3bfc62c4f91c4d892a07283eb2edf2e4dc6f459c
sha256: 7b60321b0aec8bd0d4012d5081d260cae50cdc71f7a07d59501a0e380636b35f
sha512: ffb11dc6d0befa12b9ff4611f693b75d7720ccd5fe037c0b720f246e76642021d0db67c839917df1c1a3d45a9bae55127a87a71c1f28dd20df14baa12b552aca
ssdeep: 12288:TKaKTxwBK3FoZxyCU0jZhjZrd2u5OyBc5i+6wTu76NUjgBW2S0ld:u/mBK3FoZxyCU0jZhj2iOHbFNiZ1k
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalNamed: eczvkphvesv.ixe
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbjv
Translation: 0x0842 0x04c4

Trojan-Dropper.Win32.Scrop.aczv also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKDZ.68049
FireEyeGeneric.mg.911864e5dfb40e18
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056947f1 )
BitDefenderTrojan.GenericKDZ.68049
K7GWTrojan ( 0056947f1 )
Cybereasonmalicious.4f91c4
BitDefenderThetaGen:NN.ZexaF.34128.HG0@ayhha5fc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEFS
APEXMalicious
ClamAVWin.Dropper.Vidar-8170701-0
GDataWin32.Packed.Kryptik.3Q4BM7
KasperskyTrojan-Dropper.Win32.Scrop.aczv
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKDZ.68049 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/GandCrab-G
eGambitUnsafe.AI_Score_63%
MAXmalware (ai score=86)
Antiy-AVLTrojan[Dropper]/Win32.Scrop
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Generic.D109D1
AhnLab-V3Malware/Win32.RL_Generic.R341091
ZoneAlarmTrojan-Dropper.Win32.Scrop.aczv
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!911864E5DFB4
VBA32BScope.Trojan.AET.281105
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazreLdV+boUwnMRin53cdAg4)
SentinelOneDFI – Malicious PE
FortinetW32/GandCrab.EMWT!tr
Ad-AwareTrojan.GenericKDZ.68049
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.147F.Malware.Gen

How to remove Trojan-Dropper.Win32.Scrop.aczv?

Trojan-Dropper.Win32.Scrop.aczv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment