Malware

Application.Downloadware.SES removal instruction

Malware Removal

The Application.Downloadware.SES is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Downloadware.SES virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
artistrun.top
ec2-54-154-145-223.eu-west-1.compute.amazonaws.com
www.bing.com

How to determine Application.Downloadware.SES?


File Info:

crc32: B24F4C42
md5: f2a836808245e6b501698ec1b7a37360
name: F2A836808245E6B501698EC1B7A37360.mlw
sha1: 7beae239c59f1ac16e4847fa9bdb804ed63bb75e
sha256: dd63edb414be7cc54193c6b0735f5c6089e4a1b0c05759e8eab2dcc297d524ae
sha512: 31a17f259f9f7d40fbbd03f7a98829ed1c694f8111f6f40fdd3b64ede8b51e86c58718b1949518fb12893f7c40e8e961c50fb1d0d42626e3c602afaa4e458d64
ssdeep: 3072:REuKVcu4B1CiVeLAHXEt7T7ieXPAvAg0FujGEOlcYC51YtI4mt0:RduYB1CmAAHaTm9vAOWlY51YSC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: wrWindows cross
InternalName: yeWindows cross
FileVersion: 2437.0.0.16
CompanyName: mqWindows cross
ProductName: kyWindows cross
ProductVersion: 13987.0.0.1546
FileDescription: ywWindows cross
OriginalFilename: utWindows cross
Translation: 0x0047 0x04b0

Application.Downloadware.SES also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Downloadware.SES
FireEyeGeneric.mg.f2a836808245e6b5
ALYacApplication.Downloadware.SES
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.TOVus.2!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 005195771 )
BitDefenderApplication.Downloadware.SES
K7GWTrojan-Downloader ( 005195771 )
Cybereasonmalicious.08245e
CyrenW32/S-9d8064d4!Eldorado
SymantecAdware.MediaLoad
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Malware.Razy-6988968-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.TOVus.gen
AlibabaTrojanDownloader:Win32/Tovkater.eeed03e2
NANO-AntivirusRiskware.Win32.TOVus.etqgnh
TencentMalware.Win32.Gencirc.10b1e3b9
Ad-AwareApplication.Downloadware.SES
EmsisoftApplication.Downloadware.SES (B)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.FG@7c2i4j
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.DownLoader25.54251
ZillyaAdware.TOVus.Win32.37
TrendMicroTROJ_GEN.R002C0OB321
McAfee-GW-EditionGenericRXCZ-NG!F2A836808245
SophosGeneric PUA HL (PUA)
IkarusTrojan-Downloader.Win32.Tovkater
JiangminAdWare.TOVus.bk
AviraADWARE/InstMonster.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftSoftwareBundler:Win32/InstallMonster
GridinsoftAdware.Win32.Downloader.oa
ArcabitApplication.Downloadware.SES
SUPERAntiSpywarePUP.Downloader/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.TOVus.gen
GDataApplication.Downloadware.SES
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Agent.R210613
McAfeeGenericRXCZ-NG!F2A836808245
VBA32AdWare.TOVus
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.FG
TrendMicro-HouseCallTROJ_GEN.R002C0OB321
RisingDownloader.Tovkater!8.E5CE (CLOUD)
YandexPUA.TOVus!DttBMlWQcj8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Tovkater.FH!tr.dldr
BitDefenderThetaGen:NN.ZexaF.34804.lC2@ayEMiMnI
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.845

How to remove Application.Downloadware.SES?

Application.Downloadware.SES removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment