Trojan

Win32/TrojanDropper.VB.NGV removal instruction

Malware Removal

The Win32/TrojanDropper.VB.NGV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.VB.NGV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Win32/TrojanDropper.VB.NGV?


File Info:

name: 81AA2D9AFC59AFB3C204.mlw
path: /opt/CAPEv2/storage/binaries/21104f85123b02cd425f5b1709d16538c6aa3ed983dc6273140f76a41e2b07ac
crc32: 387E36E3
md5: 81aa2d9afc59afb3c2041d1502ce400a
sha1: 7b16dc65cf20e1165df207ad2e849535ce502f6c
sha256: 21104f85123b02cd425f5b1709d16538c6aa3ed983dc6273140f76a41e2b07ac
sha512: e69c732b34a4815b3dcf68602bb1c6bd758ccf70e0a2ebcee7f79efb3f276735ccec4e1e03237939b2b9b3d11eb0c13964d5b7933247c8436f784bf798baa535
ssdeep: 1536:Y5GJEhlcbW5sk1BlfLvveIbXWm+nwN6J6D2D0qePkwMdPzE3RC19NEyzPK/et+Eq:uGu9BlfzWIbXWm+w0JW3MpHNEkPCbEq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C94F8F5E6D0DA0BF5A4B93109A0FE1E0515FB34BB22EAAB5764360A5677BC04074F0E
sha3_384: 6d625b4077461aea0ed299866c6d28d3270bb0d2418d350535cc2a5a8f4fe1f5c3369679287b155856603a9caf963b2a
ep_bytes: e80a000000e97affffffcccccccccc8b
timestamp: 2008-04-13 18:32:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0409 0x04b0

Win32/TrojanDropper.VB.NGV also known as:

LionicTrojan.Win32.Ardamax.l!c
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.VB.Krypt.13
CAT-QuickHealTrojan.VBVMF.S2280711
SkyhighGeneric VB.do
McAfeeArtemis!81AA2D9AFC59
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusHacktool ( 0052874c1 )
AlibabaTrojanDropper:Win32/Cryptor.cec9d1a4
K7GWHacktool ( 0052874c1 )
Cybereasonmalicious.afc59a
BaiduWin32.Trojan-Dropper.VB.an
VirITTrojan.Win32.VB.CAW
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDropper.VB.NGV
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Dropper.Remcos-7051626-0
KasperskyTrojan.Win32.VB.bkwm
BitDefenderGen:Heur.VB.Krypt.13
NANO-AntivirusTrojan.Win32.VB.ezgvfv
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b298c6
EmsisoftGen:Heur.VB.Krypt.13 (B)
F-SecureTrojan-Dropper:W32/Otfus.gen!A
DrWebTrojan.PWS.Multi.76
VIPREGen:Heur.VB.Krypt.13
TrendMicroMal_Poison3
Trapminesuspicious.low.ml.score
FireEyeGen:Heur.VB.Krypt.13
SophosMal/Generic-S
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.VB.asew
WebrootW32.Malware.Gen
VaristW32/Vbinder.B.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=97)
Antiy-AVLTrojan/Win32.VB.bkwm
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Ymacco
XcitiumMalware@#220zq4ntu3w3s
ArcabitTrojan.VB.Krypt.13 [many]
ZoneAlarmTrojan.Win32.VB.bkwm
GDataGen:Heur.VB.Krypt.13 (2x)
GoogleDetected
AhnLab-V3Backdoor/Win32.Bifrose.C136283
VBA32Malware-Cryptor.VB.gen.1
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallMal_Poison3
RisingTrojan.Win32.VBCode.ake (CLASSIC)
YandexTrojan.GenAsa!c5MStWXfdc4
IkarusBackdoor.Win32.VB
FortinetW32/VB.BKWM!tr
BitDefenderThetaAI:Packer.64829A551F
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:MSOffice/VB.bkwm

How to remove Win32/TrojanDropper.VB.NGV?

Win32/TrojanDropper.VB.NGV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment