Malware

What is “Application.Downloader.ANS”?

Malware Removal

The Application.Downloader.ANS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Downloader.ANS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Collects information about installed applications
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
uxqa-ui.ru

How to determine Application.Downloader.ANS?


File Info:

crc32: 00B3C94E
md5: 6cb6bfddd2e2631782cf5dcf262b65e3
name: 6CB6BFDDD2E2631782CF5DCF262B65E3.mlw
sha1: f3d655c28e18be1860a3ab35bdc5c53b18d1e159
sha256: 237ec61cd695fb411ff68b967741c15259f4b3c35d057cabbb5921af8e6b2850
sha512: aeda33966d27928dfaa2fcc57bf61c6918aaf704b4183dea8cfcf76d95257b9afafdc18bed926c666a7a8d932ab9fadbbbdad7dcf12b149184a2e737a291fe14
ssdeep: 98304:BWWe3uOEYzJI1RcWpTCFrQBXKzLo/0+AzhGgIaR:kR3uvYzJI1RcOTCrQBX6KAzhGdc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Etarisoanet ruersie
InternalName: DIEDEG.EXE
FileVersion: 2.8.5.4
CompanyName: xa9Etarisoanet ruersie
ProductName: DIEDEG
ProductVersion: 2.8.5.4
OriginalFilename: diedeg.exe
Translation: 0x0409 0x04e4

Application.Downloader.ANS also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052ffa71 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.936
CynetMalicious (score: 100)
CAT-QuickHealPUA.GenericPMF.S4847830
ALYacApplication.Downloader.ANS
ZillyaTrojan.Kryptik.Win32.1409865
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0052ffa71 )
Cybereasonmalicious.dd2e26
CyrenW32/S-65f31d20!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GGIK
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.DownloadHelper.gen
BitDefenderApplication.Downloader.ANS
NANO-AntivirusTrojan.Win32.Snojan.fbbzic
MicroWorld-eScanApplication.Downloader.ANS
TencentMalware.Win32.Gencirc.114cfd0e
Ad-AwareApplication.Downloader.ANS
SophosGeneric PUA PD (PUA)
BitDefenderThetaGen:NN.ZexaF.34294.@t0@aeKWXcni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.vh
FireEyeGeneric.mg.6cb6bfddd2e26317
EmsisoftApplication.Downloader.ANS (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Snojan.alj
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.25F975D
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataApplication.Downloader.ANS
AhnLab-V3PUP/Win32.LoadMoney.R227064
Acronissuspicious
McAfeePUP-XFI-TF
MAXmalware (ai score=96)
VBA32BScope.Downloader.Snojan
PandaTrj/GdSda.A
RisingAdware.Adload!1.B2A5 (CLASSIC)
YandexTrojan.GenAsa!Kd8h4RgVbgQ
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GDTD!tr
AVGWin32:Adware-gen [Adw]

How to remove Application.Downloader.ANS?

Application.Downloader.ANS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment