Trojan

Win32/TrojanDropper.Addrop.X removal instruction

Malware Removal

The Win32/TrojanDropper.Addrop.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Addrop.X virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win32/TrojanDropper.Addrop.X?


File Info:

name: 380F6CBDD1B2FB3EB624.mlw
path: /opt/CAPEv2/storage/binaries/a5b84cd71346fe00bb9ebd1397b05691c5d3c1b6b9f45e9776f26ff2616aa24a
crc32: D6671E78
md5: 380f6cbdd1b2fb3eb6246c5d7382cef8
sha1: f5d79784c5f886aa7a420d47c2dc7546c4c4138c
sha256: a5b84cd71346fe00bb9ebd1397b05691c5d3c1b6b9f45e9776f26ff2616aa24a
sha512: e16df2c4dfa9bfb714882ec259d33be5a29b90f30f0dede24df2ffc59e139c09bea7669691a5b686190b095dcf372d04119a10e6c51a68d789e4e9ce9bb39051
ssdeep: 12288:X9Qha9PvQNDiecUGZwef3QFBXTP7gvk+FCWoCASYoB3u:X9QKciUGZffABL7F+lojShVu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0D4232E34E141B3CF52597508A6BBBCE563CF8000107A974764EFBE5934AB6E63F449
sha3_384: 9a1aa1ae9fb88f4110a58caa85132ac621332d1a79a05b1472d35519bcf158ccc33e8ad72b3e0d449a870ac936bdd97e
ep_bytes: 81ec800100005355565733db68018000
timestamp: 2015-12-27 05:38:52

Version Info:

0: [No Data]

Win32/TrojanDropper.Addrop.X also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43714467
ALYacTrojan.GenericKD.43714467
CylanceUnsafe
SangforAdware.Win32.GenericKD.5965424
K7AntiVirusTrojan ( 00537d1c1 )
AlibabaTrojanDropper:Win32/MediaMagnet.c1562630
K7GWTrojan ( 00537d1c1 )
Cybereasonmalicious.dd1b2f
SymantecTrojan.Gen.2
ESET-NOD32Win32/TrojanDropper.Addrop.X
APEXMalicious
ClamAVWin.Adware.Mediamagnet-7062485-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.43714467
NANO-AntivirusTrojan.Win32.Addrop.ehccma
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Adware-gen [Adw]
Ad-AwareTrojan.GenericKD.43714467
SophosMal/Generic-S
ComodoMalware@#1qxsto7w7nml9
F-SecureTrojan.TR/Agent.hkbfm
DrWebPython.Bot.1
ZillyaTrojan.GenericKD.Win32.20391
McAfee-GW-EditionBehavesLike.Win32.Browser.jc
FireEyeTrojan.GenericKD.43714467
EmsisoftTrojan.GenericKD.43714467 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.43714467
WebrootW32.Trojan.GenKD
AviraTR/Agent.hkbfm
MAXmalware (ai score=99)
ArcabitTrojan.Generic.D29B07A3
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.MediaMagnet.C4158088
McAfeeGeneric.aoc
VBA32AdWare.MediaMagnet
MalwarebytesGeneric.Trojan.Malicious.DDS
TencentNsis.Adware.Mediamagnet.Lhxf
IkarusTrojan-Dropper.Win32.Addrop
FortinetRiskware/Addrop
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Win32/TrojanDropper.Addrop.X?

Win32/TrojanDropper.Addrop.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment