Malware

Should I remove “Win32:Dropper-OYD [Drp]”?

Malware Removal

The Win32:Dropper-OYD [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Dropper-OYD [Drp] virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32:Dropper-OYD [Drp]?


File Info:

name: BD745E52ED9EDB62F4C5.mlw
path: /opt/CAPEv2/storage/binaries/36a5c92617267df96e68000680f4a49adfb46443101075772a48e2f10f546332
crc32: 21EC7BF5
md5: bd745e52ed9edb62f4c5897a60ba2a52
sha1: 6748286603d5570f8e7a0c5a6f9f0f977d85c2d4
sha256: 36a5c92617267df96e68000680f4a49adfb46443101075772a48e2f10f546332
sha512: 428d091a8e3b8926d62e38fdeb09b3ba21b749bb54728d8dfd8939331ec26ce6e52aa3d7fc7406ad4fbeb616c89fb88b1ea035a6f4ad6617fd2687970e99a597
ssdeep: 768:50w981IshKQLroA4/wQozzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzX:CEGI0oAlVunMxVS3HgdoKjhLJhL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0C3C2295FEA102AF1B39670A5B156FABD3BFC5B35444D0E0183C24D4D62F01ADA6E2F
sha3_384: 5a308ccb9bf110356b300f5caa95a92229a03fc5c8e1ab9778d37dbe121e2417e36d18f8d8aa6c080da56c7491ede100
ep_bytes: 558bec6aff6898314000683026400064
timestamp: 2019-01-21 07:12:29

Version Info:

0: [No Data]

Win32:Dropper-OYD [Drp] also known as:

BkavW32.AIDetectMalware
AVGWin32:Dropper-OYD [Drp]
MicroWorld-eScanTrojan.Rincux.AW
FireEyeGeneric.mg.bd745e52ed9edb62
CAT-QuickHealPUA.StormserPMF.S20345981
SkyhighBehavesLike.Win32.Generic.cz
McAfeeGenericRXHD-CI!BD745E52ED9E
VIPRETrojan.Rincux.AW
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005b1a971 )
K7GWTrojan ( 005b1a971 )
Cybereasonmalicious.2ed9ed
BitDefenderThetaAI:Packer.CD295EF41E
VirITTrojan.Win32.Storm.GA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PIH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Ulise-9951851-0
KasperskyTrojan-DDoS.Win32.StormAttack.a
BitDefenderTrojan.Rincux.AW
NANO-AntivirusTrojan.Win32.StormAttack.fnqayj
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Dropper-OYD [Drp]
RisingDropper.Agent!1.C6A3 (CLASSIC)
SophosTroj/Agent-BIXD
F-SecureTrojan.TR/Dropper.Gen
DrWebDDoS.Storm.156
ZillyaTool.StormAttackGen.Win32.1
Trapminemalicious.high.ml.score
EmsisoftTrojan.Rincux.AW (B)
IkarusTrojan-Downloader.Win32.Pangu
JiangminTrojanDDoS.StormAttack.a
VaristW32/StormAttack.B.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Agent.pih
Kingsoftmalware.kb.a.999
MicrosoftDDoS:Win32/Stormser!pz
XcitiumTrojWare.Win32.Magania.~AAC@f80ur
ArcabitTrojan.Rincux.AW
ViRobotTrojan.Win32.Agent.61440.JD
ZoneAlarmTrojan-DDoS.Win32.StormAttack.a
GDataWin32.Trojan.PSE.SHFS16
GoogleDetected
AhnLab-V3Trojan/Win.StormAttack.92820
Acronissuspicious
VBA32BScope.TrojanDDoS.StormAttack
ALYacTrojan.Rincux.AW
TACHYONTrojan/W32.StormAttack.126976
Cylanceunsafe
TencentTrojan-Ddos.Win32.Stormattack.wa
YandexTrojan.GenAsa!WGvR5YnH2mQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.DDoS.StormAttack.a
FortinetW32/ServStart.AS!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudDDoS:Win/Stormser

How to remove Win32:Dropper-OYD [Drp]?

Win32:Dropper-OYD [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment