Virus

Should I remove “Virus:Win32/Drowor.B”?

Malware Removal

The Virus:Win32/Drowor.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Drowor.B virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Virus:Win32/Drowor.B?


File Info:

name: C135578E3E0E4C48EA80.mlw
path: /opt/CAPEv2/storage/binaries/5e88c57d2b91762919e58d93a1d5ccf61f21242f3b35820ccb8a203644465a71
crc32: D53E0916
md5: c135578e3e0e4c48ea803f84cd81a3f9
sha1: 0cd37b8d513f20519a551f80abf5ff9e22ca5dc3
sha256: 5e88c57d2b91762919e58d93a1d5ccf61f21242f3b35820ccb8a203644465a71
sha512: eafba8946cd6234318a3069a6cc725e63f4f83ccbf466fd76ae941384240e43863453a81c99f5d87ca990a48db4a5673de51d5f2b7ead3d19a2875d7d648e3bb
ssdeep: 3072:ftvvBmh7MlSum5158ijSi18/J0khOKqmJOVXtPSjnc5INh4Rq5L/cI768G7KKkkG:lR27i9mD3yJidmJOVsjnc6N0rI79KrZG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109040253F1B73026DFC1A43C98D5F335230A99A80A2BAEBB291B6C9E7D305C65D75312
sha3_384: 9aa781af4a73c47bff574def18bc9d67d993ca43658d6045645ee6c123595dab01d4e11b31f52da52cce907f815af997
ep_bytes: e98ffcffffd6c10b9b989b9b9b9f9b9b
timestamp: 2007-01-06 18:39:58

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: File Folder
OriginalFilename: File Folder.exe

Virus:Win32/Drowor.B also known as:

BkavW32.TnIndoVS.PE
LionicWorm.Win32.Trafaret.kZSZ
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Kunkka.A
ClamAVWin.Worm.Trafox-1
CAT-QuickHealW32.Drowor.C
SkyhighBehavesLike.Win32.Backdoor.cc
McAfeeW32/Cekar.j
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 000f9fff1 )
AlibabaMalware:Win32/km_22e92.None
K7GWVirus ( 000f9fff1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWorm.Win32.VB.G
SymantecW32.Drowor.B!inf
tehtrisGeneric.Malware
ESET-NOD32Win32/Troxa.B
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Trafaret.a
BitDefenderWin32.Kunkka.A
NANO-AntivirusVirus.Win32.Drowor.bmmqn
AvastWin32:Trojan-gen
TencentVirus.Win32.Dropper.aa
EmsisoftWin32.Kunkka.A (B)
F-SecureMalware.W32/Sality.S
DrWebWin32.Fortax
VIPREWin32.Kunkka.A
TrendMicroPE_DROWOR.A
FireEyeGeneric.mg.c135578e3e0e4c48
SophosW32/Drowor-A
IkarusTrojan.Crypt
GDataWin32.Kunkka.A
JiangminWin32/Drowor.a
GoogleDetected
AviraW32/Sality.S
Antiy-AVLTrojan/Win32.Troxa
KingsoftWin32.Trafaret.a.19825
XcitiumWorm.Win32.Trafaret.a0@1bslw8
ArcabitWin32.Kunkka.A
ViRobotWin32.Trafaret.B
ZoneAlarmWorm.Win32.Trafaret.a
MicrosoftVirus:Win32/Drowor.B
VaristW32/Seriv.A
AhnLab-V3Worm/Win32.AutoRun.R2381
BitDefenderThetaAI:FileInfector.0A6F0E920E
ALYacWin32.Kunkka.A
MAXmalware (ai score=83)
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallPE_DROWOR.A
RisingWin32.Troxa.a (CLASSIC)
YandexWin32.Troxa.A
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Trafaret.A
FortinetW32/Troxa.A
AVGWin32:Trojan-gen
Cybereasonmalicious.d513f2
DeepInstinctMALICIOUS

How to remove Virus:Win32/Drowor.B?

Virus:Win32/Drowor.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment