Trojan

TrojanDropper.MSIL.Gendwndrop removal guide

Malware Removal

The TrojanDropper.MSIL.Gendwndrop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper.MSIL.Gendwndrop virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanDropper.MSIL.Gendwndrop?


File Info:

crc32: 1354145C
md5: ac7c855c17954a97104fc2647b77365b
name: captain_coochie.exe
sha1: 8789bc8139aeb12f53fda849bc7f314eae44e128
sha256: d49e98eccd8bf626b9589284ad9c259d4268b2f14d81fda25481f912f9d7bea9
sha512: 209b5aa4917c3dd8b60d2772514be72cd6684e5afd953aa1679f1bfa0818433db51609dffe8d59a2daeb31ace4873b9005c17050e902aacbd6e55d9c5479b278
ssdeep: 192:sLYYbtYpmksk2oG6RmGrUaHI5SESkrUV0q1UEJeKzhCm:olG2GrUaHsSEbrUyU9C
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: captain coochie.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: captain coochie.exe

TrojanDropper.MSIL.Gendwndrop also known as:

MicroWorld-eScanGen:Variant.Razy.158706
FireEyeGeneric.mg.ac7c855c17954a97
CAT-QuickHealTrojan.MSIL
Qihoo-360Generic/Trojan.GameThief.9bb
McAfeeGenericRXBX-DS!AC7C855C1795
MalwarebytesSpyware.OnlineGames.MSIL
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.158706
K7GWTrojan ( 700000121 )
Cybereasonmalicious.c17954
Invinceaheuristic
F-ProtW32/Razy.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Razy.158706
KasperskyHEUR:Trojan-GameThief.MSIL.Agent.gen
AlibabaTrojanDropper:MSIL/Gendwndrop.ff40adce
NANO-AntivirusTrojan.Win32.OnLineGames.eovftk
AegisLabTrojan.MSIL.Agent.d!c
TencentMsil.Trojan-gamethief.Agent.Lors
Ad-AwareGen:Variant.Razy.158706
SophosMal/Generic-S
ComodoTrojWare.MSIL.Gendwndrop.BAT@7lxgqp
F-SecureHeuristic.HEUR/AGEN.1101064
DrWebTrojan.Siggen6.63994
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R049C0DFG20
EmsisoftGen:Variant.Razy.158706 (B)
IkarusTrojan.MSIL.PSW
CyrenW32/Razy.CK.gen!Eldorado
JiangminTrojan.PSW.MSIL.aefy
AviraHEUR/AGEN.1101064
MAXmalware (ai score=87)
Antiy-AVLTrojan[GameThief]/MSIL.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D26BF2
ZoneAlarmHEUR:Trojan-GameThief.MSIL.Agent.gen
MicrosoftTrojanDropper:MSIL/Gendwndrop.M!bit
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZemsilF.34130.am0@aOhlnp
ALYacGen:Variant.Razy.158706
VBA32TrojanDropper.MSIL.Gendwndrop
CylanceUnsafe
ESET-NOD32a variant of MSIL/PSW.OnLineGames.BAT
TrendMicro-HouseCallTROJ_GEN.R049C0DFG20
RisingStealer.OnLineGames!8.131 (CLOUD)
YandexTrojan.PWS.OnLineGames!/o29ZREtp9o
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetMSIL/Generic.AP.8614B0!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove TrojanDropper.MSIL.Gendwndrop?

TrojanDropper.MSIL.Gendwndrop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment