Trojan

How to remove “UDS:Trojan-Dropper.Win32.Pasnaino”?

Malware Removal

The UDS:Trojan-Dropper.Win32.Pasnaino is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Dropper.Win32.Pasnaino virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine UDS:Trojan-Dropper.Win32.Pasnaino?


File Info:

name: 772DBAC64EF8E32F626E.mlw
path: /opt/CAPEv2/storage/binaries/5bc23cb22106bfe8651dc5fb71941ad6568a0eedfefb44465df76ff296e66c12
crc32: DB26F90E
md5: 772dbac64ef8e32f626e2f051227ffd6
sha1: 31ecebbd8c26ec1236da55e93881e5bc556356a4
sha256: 5bc23cb22106bfe8651dc5fb71941ad6568a0eedfefb44465df76ff296e66c12
sha512: 75b769dbb81fc6422be69c47182c0cfa1561d9ec7d4a6f8a8a48618873c4c16af7ade132899eeec6ff4d1e26bc2dbf923afe93bf51e247838f265f4739c50582
ssdeep: 12288:uaHc64b888888888888W88888888888loscV7/9GqeMo3yM5oOoQV33rD+zG/oBe:F86wjW7/9oyTfQpezG/aYFkJR30F6rpI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9F40213B3C30032F5261A35CDB680449D27797949F0605A2EF9EB4E4EBA7C69D7BB21
sha3_384: aea221053e9682f9a3c8d27e294a2b598828f6c34f335e05ffb170551f0a887039e72ed6423df839e43e6643534bc30e
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion: 1.2
LegalCopyright:
ProductName:
ProductVersion: 1.2
Translation: 0x0000 0x04b0

UDS:Trojan-Dropper.Win32.Pasnaino also known as:

LionicTrojan.Win32.Addrop.b!c
AVGWin32:Malware-gen
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Dropper.bc
McAfeeArtemis!772DBAC64EF8
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
AlibabaTrojanDropper:Win32/Addrop.abbec2f9
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Addrop.CH
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Malware.Ejfb-9784212-0
KasperskyUDS:Trojan-Dropper.Win32.Pasnaino.gen
AvastWin32:Malware-gen
TencentTrojan.Win32.MalCrack.haw
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen8
IkarusTrojan-Dropper.Addrop
JiangminTrojanDropper.Agentino.a
VaristW32/Addrop.D.gen!Eldorado
AviraTR/Crypt.XPACK.Gen8
Kingsoftmalware.kb.a.987
MicrosoftTrojan:Win32/Phonzy.C!ml
ZoneAlarmUDS:Trojan-Dropper.Win32.Pasnaino.gen
AhnLab-V3PUP/Win32.Generic.C2712904
MalwarebytesTrojan.Dropper
RisingDownloader.TaskLoader/ARCHIVE!1.CDEA (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Addrop.CH!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudTrojan[dropper]:Win/Addrop.CH

How to remove UDS:Trojan-Dropper.Win32.Pasnaino?

UDS:Trojan-Dropper.Win32.Pasnaino removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment