Trojan

Trojan.Dropper.ZFE removal guide

Malware Removal

The Trojan.Dropper.ZFE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.ZFE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Dropper.ZFE?


File Info:

name: C7BFC96B3E8124E07925.mlw
path: /opt/CAPEv2/storage/binaries/789df0794dc899ab79d4501b025761d013e56eba8f2439ee9705d1c1ee17d069
crc32: 3D90BDB8
md5: c7bfc96b3e8124e07925da173c7c18ff
sha1: 557f42482ebc126ba2d46a21b1307f802e76428a
sha256: 789df0794dc899ab79d4501b025761d013e56eba8f2439ee9705d1c1ee17d069
sha512: cf0f5561eb30c58e492b90c9509253bf5871bbec19f851e67624d0cb970a8e2e65bef22edffe65715ca6a13561c2b3215fd1ed4186608a7bef0291ee8ac68987
ssdeep: 6144:3F5P1Z8pvPjijr3KkuSWZTCDL6utVmGvvD5CfSqDm4FuIrL3xfMudgd:3F11Z4Pjij2BBTW2utV/T5CpDJJMX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19574234E7B142961CC3E7D75285B1366EE01FE7AA1E5420F01E2F50E9C8A75D8BAB1C3
sha3_384: 906b896f23dac1098f90be7d25fd8ab7cfdd23fb9206446ecfa048b6cee072db4231789d2424d46d1a0e20f9c727a357
ep_bytes: 60be004048008dbe00d0f7ff57eb0b90
timestamp: 2018-01-06 09:49:19

Version Info:

0: [No Data]

Trojan.Dropper.ZFE also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Crypt.4!c
CynetMalicious (score: 100)
ALYacTrojan.Dropper.ZFE
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.AutoHK.8
K7AntiVirusTrojan-Downloader ( 0052f72c1 )
AlibabaTrojanDownloader:MSIL/Codiby.90faf6eb
K7GWTrojan-Downloader ( 0052f72c1 )
Cybereasonmalicious.b3e812
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.AutoHK.GG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Agen-9836298-0
KasperskyTrojan.MSIL.Crypt.gqpi
BitDefenderTrojan.Dropper.ZFE
NANO-AntivirusTrojan.Win32.Crypt.fayhyt
MicroWorld-eScanTrojan.Dropper.ZFE
TencentMsil.Trojan.Crypt.Taff
SophosMal/Generic-S
ComodoMalware@#w6a01fq1j6po
DrWebTrojan.DownLoader32.59441
ZillyaAdware.Codiby.Win32.1016
TrendMicroTROJ_GEN.R002C0GAJ22
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeTrojan.Dropper.ZFE
EmsisoftTrojan.Dropper.ZFE (B)
IkarusTrojan-Downloader.Win32.Autohk
JiangminRiskTool.BitMiner.udv
AviraHEUR/AGEN.1207883
Antiy-AVLTrojan/Generic.ASMalwS.252BCB5
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmTrojan.MSIL.Crypt.gqpi
GDataTrojan.Dropper.ZFE
AhnLab-V3Malware/Win32.Generic.C4004945
McAfeeArtemis!C7BFC96B3E81
MAXmalware (ai score=83)
VBA32BScope.Trojan.Bitrep
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0GAJ22
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoHK.GG!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Dropper.ZFE?

Trojan.Dropper.ZFE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment