Trojan

Trojan-Dropper.Win32.Scrop.ahoy removal instruction

Malware Removal

The Trojan-Dropper.Win32.Scrop.ahoy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Scrop.ahoy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • The following process appear to have been packed with Themida: IntelRapid.exe, far.exe
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Scrop.ahoy?


File Info:

crc32: 4701F7C4
md5: f1b4d4902447ce5caab448a1ceea1279
name: F1B4D4902447CE5CAAB448A1CEEA1279.mlw
sha1: 8cc16603412373abe9733661949c8e7e68cbbfc0
sha256: 82986179159fb1244b89a23ab01b915fe1c24407712c156a087fe902572a4a8f
sha512: 96a94bc33c690bb6f43bcda3b9dcb6c8e77bec534f09a1c6d5f7d6830a0cee64cb18d8d42a3efb70500e405beee245276307881ef87099ae6bfc954a52a069cf
ssdeep: 98304:dZihAT0yIsO/Wjyzn3fizXpogVw3I5gWIaeoMlbMBF:dUhO0yrO+a3filzx5gSejQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: hereon
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Trojan-Dropper.Win32.Scrop.ahoy also known as:

LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.35617
ClamAVWin.Packed.Filerepmalware-9864117-0
McAfeeArtemis!F1B4D4902447
ZillyaTrojan.Racealer.Win32.1307
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Themida.4cc6e809
K7GWTrojan ( 005816021 )
K7AntiVirusTrojan ( 005816021 )
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Scrop.ahoy
BitDefenderTrojan.GenericKD.37476574
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanTrojan.GenericKD.37476574
TencentWin32.Trojan-qqpass.Qqrob.Ecto
Ad-AwareTrojan.GenericKD.37476574
SophosMal/Generic-R
ComodoTrojWare.Win32.UMal.qeqtd@0
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaAI:Packer.B0BB50EF1E
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.PUPXGH.wc
FireEyeTrojan.GenericKD.37476574
EmsisoftTrojan.GenericKD.37476574 (B)
AviraBDS/Agent.gyfxh
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.BSE.HLJWVB
AhnLab-V3Trojan/Win.Trojan-gen.C4442892
VBA32BScope.TrojanRansom.Foreign
MAXmalware (ai score=86)
MalwarebytesMalware.AI.3005362190
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R06CH07HO21
RisingTrojan.Generic@ML.100 (RDML:udbAU9pBwAcmTsInMaiXKA)
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Dropper.Win32.Scrop.ahoy?

Trojan-Dropper.Win32.Scrop.ahoy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment