Malware

Win32:Dropper-NGT [Drp] information

Malware Removal

The Win32:Dropper-NGT [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Dropper-NGT [Drp] virus can do?

  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:Dropper-NGT [Drp]?


File Info:

name: B452EAAADB78DF209673.mlw
path: /opt/CAPEv2/storage/binaries/df11f8cb888e21ad2e52d26972564dcad41d7be5bf42f08cf131d88a974b0675
crc32: A4F9BA28
md5: b452eaaadb78df209673d96235952fd3
sha1: 21187b8ab2e39181ba0b3bb96c89af4394e98674
sha256: df11f8cb888e21ad2e52d26972564dcad41d7be5bf42f08cf131d88a974b0675
sha512: 582a7a94c61182fcf424568cd56827e00a04cc766ced7c3566f8446b0eeebf926b0b101681ebc8af37951c4d13ac73c16a4d0d0bed1226a387c9fd22abc2099d
ssdeep: 6144:xDKHpICd4Gp9r6zedtFUWLTEsniHLrFPjHeYvBO/LF2xZPdZJFjx:pKJz2edtFUWEsniHtTrhLL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE64AF223690C037E376177148C5E6B46AA5BC3159A5970FFBA47B399E301938B2B34F
sha3_384: d0b6df39feb444c6a6f8f6992356eaf2dd24c5a7f16465716dab1b1f0044598fb234e5c787c4c0adabecea3c58d5ce3f
ep_bytes: e80da10000e979feffff8bff558bec51
timestamp: 2013-10-09 07:43:47

Version Info:

0: [No Data]

Win32:Dropper-NGT [Drp] also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.426059
ClamAVWin.Packed.Urelas-9879149-0
FireEyeGeneric.mg.b452eaaadb78df20
ALYacGen:Variant.Zusy.426059
Cylanceunsafe
ZillyaTrojan.Urelas.Win32.42918
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36132.umW@a4zu4BiO
CyrenW32/Urelas.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.W
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Plite.bhum
BitDefenderGen:Variant.Zusy.426059
NANO-AntivirusTrojan.Win32.Plite.ewdrfz
AvastWin32:Dropper-NGT [Drp]
TencentTrojan.Win32.Agent.aep
TACHYONDropper/W32.Plite.333824
SophosMal/Generic-S
BaiduWin32.Trojan.Urelas.a
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.AVKill.33487
VIPREGen:Variant.Zusy.426059
TrendMicroTrojan.Win32.Urelas.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.426059 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1CYCYN2
JiangminBackdoor.Generic.zpu
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan[Backdoor]/Win32.Plite
XcitiumTrojWare.Win32.Gupboot.BB@53dg1h
ArcabitTrojan.Zusy.D6804B
ZoneAlarmBackdoor.Win32.Plite.bhum
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R493701
McAfeeBackDoor-FBLQ!B452EAAADB78
MAXmalware (ai score=83)
MalwarebytesCrypt.Trojan.Malicious.DDS
TrendMicro-HouseCallTrojan.Win32.Urelas.SM
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.O!tr
AVGWin32:Dropper-NGT [Drp]
DeepInstinctMALICIOUS

How to remove Win32:Dropper-NGT [Drp]?

Win32:Dropper-NGT [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment