Home Malware Programs Trojans Generic Dropper.p

Generic Dropper.p

Posted: November 5, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 28
First Seen: November 5, 2012
Last Seen: December 3, 2021
OS(es) Affected: Windows

Generic Dropper.p is a generic label for a Trojan dropper that installs malicious software onto your computer – either without your consent or by misrepresenting its payload as beneficial. Even though Generic Dropper.p can be used in an immense range of attacks, the most recent Generic Dropper.p activities have centered on e-mail spam attacks that appear to be targeted at Middle Eastern law enforcement agencies. After being launched, Generic Dropper.p installs a variant of the Artemis Trojan on the affected PC. SpywareRemove.com malware experts recommend a dual strategy for handling Generic Dropper.p: keeping your e-mail security practices at reasonable levels and using anti-malware programs to remove Generic Dropper.p (along with its payload) if you do happen to get your PC infected.

Don't Let Generic Dropper.p Drop the Boot on Your Hard Drive

Generic Dropper.p is a name that can be applied to many similar variants of Trojan droppers – the vast majority of which have been reported to attack PCs based in the United States. Some of the aliases that Generic Dropper.p can be detected by include W32/Suspicious_Gen4.XXCQ, Trojan-Dropper.Win32.Agent.gnym, TR/Dropper.Gen and Trojan:Win32/Agent.KO. E-mail messages are the most common means of encountering Generic Dropper.p, but instant messenger spam, social networking site spam, malicious sites and compromised websites are other potential infection points.

Despite its tendency to attack US targets, Generic Dropper.p's most recent attack was targeted at Israeli police officials. This attack was disguised as an e-mail message sent by the head of the IDF and included Generic Dropper.p as a file attachment. Because this infection vector is extremely common for many types of Trojans besides Generic Dropper.p, SpywareRemove.com malware experts note that using anti-malware programs to scan suspicious files before opening them is one of the finest plan of action you can use to guard your PC against similar threats.

The Weight of the Stomp in Generic Dropper.p's Payload

Generic Dropper.p installs a variant of the Artemis Trojan, Artemis!2BFE41D7FDB6. SpywareRemove.com malware research team is still analyzing Artemis!2BFE41D7FDB6's payload, but also note that similar attacks against government-based targets tend to include spyware functions that steal confidential data, disrupt communications or damage computer systems. Examples of similar PC threats include the Flame virus, Gauss, Stuxnet, Wiper, Shamoon and Disttrack, all of which also were noted for their involvement in Middle East-based attacks against high-profile targets. The label Artemis!2BFE41D7FDB6 is specific to Generic Dropper.p's variant of Artemis, but other variants of Artemis Trojans also have been seen using other means of distribution.

Because Generic Dropper.p and its Artemis variant have a high chance of including highly-invasive functions, removing Generic Dropper.p and its payload with anti-malware software is recommended ASAP. However, since government and industry-specific malware attacks tend to use sophisticated defenses and may harm your computer if they're removed improperly, manual removal shouldn't be undertaken unless some assistance from PC security professionals is available.

Aliases

Trj/CI.A [Panda]Win32/Cryptor [AVG]W32/Dapato.CBXN!tr [Fortinet]Virus.Win32.Cryptor [Ikarus]TR/Drop.Dapato.cbxn [AntiVir]Trojan.PWS.Panda.3744 [DrWeb]Troj/Agent-AATB [Sophos]Trojan-Dropper.Win32.Dapato.cbxn [Kaspersky]Trojan Horse [Symantec]W32/Dorkbot.BAA!tr [Fortinet]TrojanDropper.Injector.gfes [CAT-QuickHeal]Trj/OCJ.A [Panda]Dropper.Generic7.MFT [AVG]W32/Injector.GFES!tr [Fortinet]Worm.Win32.Dorkbot [Ikarus]
More aliases (40)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\5b150187-0f05-4c72-917c-77c8e6964ac4.exe File name: 5b150187-0f05-4c72-917c-77c8e6964ac4.exe
Size: 110.59 KB (110592 bytes)
MD5: 3ceb3c3bb6c636a1a46a34e3a6e24be3
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 22, 2013
%APPDATA%\C.exe File name: C.exe
Size: 204.8 KB (204800 bytes)
MD5: 677fec3d9a46d2d4f5f5fa6591118008
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 16, 2013

One Comment

Loading...