Trojan

About “Trojan.Dropper.WXT.Generic” infection

Malware Removal

The Trojan.Dropper.WXT.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.WXT.Generic virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Dropper.WXT.Generic?


File Info:

crc32: A9AFF210
md5: 9f4e980ca07098c43941b785cfaab554
name: drop.bin
sha1: f0b82cff0943a8ba1bd570626c8263644471bffb
sha256: 747f859a8239727c0b3332c71cf98d651fb13e3e93935693acd6b8a466bb7004
sha512: 6c77b2f1cc314b12a9e31eb7f4175d558f0ac9e481673bdd998a75fd3293cd1445b86bbc5b7de7dd7306fd6fa6ff34a9e57f7659ce4e5d2a45d81d06771cb76f
ssdeep: 3072:KKy+bnr+O185GWp1icKAArDZz4N9GhbkrNEk1/X0aoQ:KKy+bnr+Dp0yN90QEm0N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan.Dropper.WXT.Generic also known as:

MicroWorld-eScanTrojan.GenericKD.33380906
FireEyeGeneric.mg.9f4e980ca07098c4
Qihoo-360Win32/Trojan.Dropper.528
McAfeeRDN/Generic Dropper
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005613b41 )
BitDefenderTrojan.GenericKD.33380906
K7GWTrojan ( 005613b41 )
Cybereasonmalicious.f0943a
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EKTY
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33380906
KasperskyHEUR:Trojan-Dropper.Win32.Dorifel.vho
AlibabaTrojanDropper:Win32/GenKryptik.85914621
AegisLabTrojan.Win32.Dorifel.b!c
TencentWin32.Trojan-dropper.Dorifel.Hvte
Ad-AwareTrojan.GenericKD.33380906
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.VB.Gen
Invinceaheuristic
McAfee-GW-EditionRDN/Generic Dropper
SentinelOneDFI – Suspicious
EmsisoftTrojan.GenericKD.33380906 (B)
APEXMalicious
CyrenW32/Trojan.QRMU-6676
WebrootW32.Trojan.Gen
AviraTR/Kryptik.knnye
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FD5A2A
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dorifel.vho
MicrosoftTrojan:Win32/Occamy.C
ALYacTrojan.GenericKD.33380906
MAXmalware (ai score=85)
MalwarebytesTrojan.Dropper.WXT.Generic
PandaTrj/CI.A
RisingDropper.Dorifel!8.31E (CLOUD)
IkarusTrojan-Spy.Agent
FortinetW32/Dorifel.EDRQ!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan.Dropper.WXT.Generic?

Trojan.Dropper.WXT.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment