Trojan

TrojanDropper:Win32/BindFile removal instruction

Malware Removal

The TrojanDropper:Win32/BindFile is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/BindFile virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine TrojanDropper:Win32/BindFile?


File Info:

name: A9D2C686EA84876BAF85.mlw
path: /opt/CAPEv2/storage/binaries/63ce6aca55b6148b6283e083da060cef3de9b454c3e9b2fa66f7ab77aaf2d9b7
crc32: 75342471
md5: a9d2c686ea84876baf85d544ed911061
sha1: 3159dffa0d4ece0e672aa3621b801c5637de3555
sha256: 63ce6aca55b6148b6283e083da060cef3de9b454c3e9b2fa66f7ab77aaf2d9b7
sha512: 19bf870e0896c61ae23b50ae202a1b6881d05fba47f843ea2085b32585871eed725ed5b7c5c4287a26d01bb142e16e70bb9a853945af9e91079d6d74e7eb6a0b
ssdeep: 3072:PJN/kjCrgq0N442wUiNaGPEUgaraD2t3VVQ/o8Wonnn:PJJNlyZUiNvM3JD2En
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104044AD17CDD88F2E146C1340DD17A76A271E83477A3CBA7A3A0DA1ADD3A7C2163B215
sha3_384: e2e20ec6ac922660e0209f9d71f51e511284eb4c037116583289f6026bb85dbe104058ec1e6e18f6b80682a1df2887b4
ep_bytes: 558bec6aff68b0ef41006880af400064
timestamp: 2031-05-20 20:54:01

Version Info:

Comments: 可用来将二个不同的可执行文件合并成一个文件,运行合并后的文件等同于同时运行合并前的二个文件。 徐景周(jingzhou_xu@163.net)
CompanyName: 未来工作室(Future Studio)
FileDescription: 可用来将二个不同的可执行文件合并成一个文件。
FileVersion: 1, 0, 0, 0
InternalName: 文件捆绑器
LegalCopyright: 版权所有(C) 2001 未来工作室
LegalTrademarks: 免费软件,谢谢使用!
OriginalFilename: BindFile.EXE
PrivateBuild: 作者:徐景周
ProductName: 文件捆绑器
ProductVersion: 1, 0, 0, 0
SpecialBuild: 作者:徐景周
Translation: 0x0404 0x04b0

TrojanDropper:Win32/BindFile also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.b!c
MicroWorld-eScanGen:Variant.Graftor.51865
SkyhighBehavesLike.Win32.Infected.ch
McAfeeArtemis!A9D2C686EA84
MalwarebytesGeneric.Malware/Suspicious
ZillyaDropper.Agent.Win32.439648
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/BindFile.262adc80
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Graftor.DCA99
BitDefenderThetaGen:NN.ZexaF.36608.lq0@aS3RjRib
VirITTrojan.Win32.Bindfile.A
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SUI
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.Win32.Agent.bjd
BitDefenderGen:Variant.Graftor.51865
NANO-AntivirusTrojan.Win32.Drop.eswaid
AvastWin32:Malware-gen
TencentWin32.Trojan-Dropper.Agent.Pgil
EmsisoftGen:Variant.Graftor.51865 (B)
F-SecureTrojan.TR/Drop.BindFile.tovmp
VIPREGen:Variant.Graftor.51865
Trapminesuspicious.low.ml.score
FireEyeGen:Variant.Graftor.51865
IkarusTrojan-Dropper.Win32.BindFile
JiangminTrojanDropper.Agent.glkz
GoogleDetected
AviraTR/Drop.BindFile.tovmp
Antiy-AVLTrojan[Dropper]/Win32.Agent
XcitiumMalware@#3jim8e820qqnw
MicrosoftTrojanDropper:Win32/BindFile
ZoneAlarmTrojan-Dropper.Win32.Agent.bjd
GDataGen:Variant.Graftor.51865
AhnLab-V3Dropper/Win32.BindFile.R22518
VBA32suspected of Backdoor.PcClient.8
ALYacGen:Variant.Graftor.51865
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/GdSda.A
RisingDropper.Agent!8.2F (TFE:5:36b8a5HEpCT)
YandexTrojan.GenAsa!+d0+XGDgmGI
MaxSecureTrojan.Malware.956033.susgen
FortinetW32/Agent.BJD!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/BindFile?

TrojanDropper:Win32/BindFile removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment