Trojan

Trojan.Dropper removal

Malware Removal

The Trojan.Dropper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Trojan.Dropper?


File Info:

crc32: 904F4F54
md5: 9def5c0f7a49a172bb82b0bee6cbc6dd
name: svch.exe
sha1: a0c41a963eecf20cd1cef8531f5962ab6ba7c2d1
sha256: b3c91cc7cc609e9b5a33dcb0faf8c43216f5d901e31b8693e234a21f418f5ae7
sha512: f30bf806d9a54960c48349285b394f1279b7f2e365c93cbe7b52b048b5c1c7bd2a1afabc0e5fc17f765e8f585dda6275c6f01e223bb19aa556c2905b17cb70f8
ssdeep: 12288:xWX+y9uX/qYuniOWRRmBQ3fJU4KdfIP8DdUP+bIHsmp:XXSviOWvmBQq4Kd+8D2+esmp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Mozido 2006-2014 (c)
FileVersion: 5.6.8.8
CompanyName: Mozido
FileDescription: Filteringsuch Junior Sysklgd Tonight Will
ProductName: Xamlparseexceptin Fkpstcmment
Languages: English
ProductVersion: 5.6.8.8
PrivateBuild: 5.6.8.8
OriginalFilename: Xamlparseexceptin Fkpstcmment.exe
Translation: 0x0409 0x04b0

Trojan.Dropper also known as:

MicroWorld-eScanTrojan.GenericKD.32797758
FireEyeGeneric.mg.9def5c0f7a49a172
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055d1041 )
BitDefenderTrojan.GenericKD.32797758
K7GWTrojan ( 0055d1041 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32797758
KasperskyTrojan.MSIL.DOTHETUK.vxt
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (moderate confidence)
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen2.40374
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
EmsisoftTrojan.GenericKD.32797758 (B)
CyrenW32/Trojan.GSDC-7734
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Generic.D1F4743E
ZoneAlarmTrojan.MSIL.DOTHETUK.vxt
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3639449
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.32797758
Ad-AwareTrojan.GenericKD.32797758
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.DZRL
TrendMicro-HouseCallTROJ_GEN.R023C0PLC19
IkarusTrojan-Spy.Remcos
MaxSecureTrojan.Malware.74734022.susgen
FortinetW32/Kryptik.GVSM!tr
BitDefenderThetaGen:NN.ZexaF.33550.KmKfaeUaBKfi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.5de

How to remove Trojan.Dropper?

Trojan.Dropper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment