Malware

Win32:Dropper-NDR [Drp] removal guide

Malware Removal

The Win32:Dropper-NDR [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Dropper-NDR [Drp] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32:Dropper-NDR [Drp]?


File Info:

name: BE760806058DDD4A5937.mlw
path: /opt/CAPEv2/storage/binaries/e496692c8e86a5a819eaddcfac84d4cb8a81ef5acfea39fca7d81f540d0249ac
crc32: 6D11F420
md5: be760806058ddd4a5937216f8e537065
sha1: b4480d6e6dc4051d0b83728928340687547e8106
sha256: e496692c8e86a5a819eaddcfac84d4cb8a81ef5acfea39fca7d81f540d0249ac
sha512: 9fb2ffc57ac024b1f4869c042e486166810a61dd07f584e263b12a48731d3689e48229d428ad5ed29002ba768df9011030b64e160461ba0570856641c8c4e3bc
ssdeep: 6144:96xwSR5NtUIJEWyXuew+q1l0d2Js6H5/TZkM:9A3NtUISdPw+Elq2Jsm2M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DA585D4C156BE39C38729BAD024EE0610362DD4F366C4BBF87B7281FAB56C2356492D
sha3_384: 646b2f48ab3ab27c5f3dcb82ff83493d2550ce2958e2bb0459cb6cdf3d7db131b556f785496029600488a0a53ef79e88
ep_bytes: b8b47e46005064ff3500000000648925
timestamp: 2013-09-12 12:25:44

Version Info:

0: [No Data]

Win32:Dropper-NDR [Drp] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.be760806058ddd4a
CAT-QuickHealTrojan.Gupboot.G.mue
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusBackdoor ( 0053e8561 )
K7GWBackdoor ( 0053e8561 )
Cybereasonmalicious.6058dd
BaiduWin32.Rootkit.Agent.s
VirITTrojan.Win32.Generic.CXD
CyrenW32/Coxy.A.gen!Eldorado
ESET-NOD32a variant of Win32/Urelas.T
APEXMalicious
ClamAVWin.Trojan.Agent-1196432
KasperskyBackdoor.Win32.Plite.bhuu
BitDefenderGen:Heur.Mint.SP.Urelas.1
NANO-AntivirusTrojan.Win32.Plite.ekcbps
AvastWin32:Dropper-NDR [Drp]
TencentTrojan.Win32.Urelas.16000132
Ad-AwareGen:Heur.Mint.SP.Urelas.1
ComodoTrojWare.Win32.Small.NAF@531prv
DrWebTrojan.AVKill.33057
ZillyaTrojan.Urelas.Win32.778
TrendMicroTROJ_GUPBOOT_EJ30000A.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Urelas-AA
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.SP.Urelas.1
JiangminBackdoor.Generic.zzv
AviraBDS/Backdoor.Gen7
MAXmalware (ai score=83)
ArcabitTrojan.Mint.SP.Urelas.1
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Backdoor/Win.Plite.C5146454
McAfeeGenericRXAA-AA!BE760806058D
VBA32BScope.Trojan.AVKill
TrendMicro-HouseCallTROJ_GUPBOOT_EJ30000A.UVPM
RisingBackdoor.Plite!8.2D6 (TFE:dGZlOgRD8UEXiDgjsA)
YandexTrojan.Urelas!ckOgVXNf57s
IkarusTrojan.Win32.Gupboot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.O!tr
BitDefenderThetaGen:NN.ZexaF.34712.@jZfaCJ2vceO
AVGWin32:Dropper-NDR [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Dropper-NDR [Drp]?

Win32:Dropper-NDR [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment