Malware

Downloader.19 (file analysis)

Malware Removal

The Downloader.19 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.19 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Downloader.19?


File Info:

name: 4BEFD56D22727ACB9B27.mlw
path: /opt/CAPEv2/storage/binaries/18080bdf305d31c63a06f975bccf83dd438c14428d7a967a831253ceb9e5f10c
crc32: BA0716D1
md5: 4befd56d22727acb9b2784e1ee753f5d
sha1: 632ca8da5c4c29f0e712e0a455f5b8f9d8cf8aac
sha256: 18080bdf305d31c63a06f975bccf83dd438c14428d7a967a831253ceb9e5f10c
sha512: 7d8cd5352cf43565be4bdd4e389ffe03962995bc583cc9939a8e5ac5af7da01ceafc7ac23122144fd856df871ee5160f34912f6c0de1b043f5718febc973c3cf
ssdeep: 384:Q98xUHQFXkenLvay4Ng8zLeijerUTy3XHnWsIjdgXZpKaC6+wTrUg20wiPg:Twira/gop9EIdgXCZwMg28Pg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7E27C5EAF9B14ABF16289B0D2F686C59BFC7C673697A83FDF40114214A5044E0A1EF1
sha3_384: 7ef37924d4559f5b94f05e517ecedc3795242e6f52c03b4fc1b09efb82b70330ada85ed6ad1ab6046985fcafe3e400d7
ep_bytes: 558bec81ec380300005356576a4033db
timestamp: 2010-08-30 02:41:44

Version Info:

CompanyName: Adobe Systems, Inc.
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
FileVersion: 10,1,53,64
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
LegalTrademarks: Adobe? Flash? Player
OriginalFilename: FlashUtil.exe
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
Translation: 0x0409 0x04b0

Downloader.19 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Downloader.19
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Downloader.nm
McAfeeDownloader-BIJ.a
Cylanceunsafe
VIPREGen:Variant.Downloader.19
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056e8c61 )
K7AntiVirusTrojan-Downloader ( 0040f54b1 )
BaiduWin32.Trojan.Inject.bm
VirITTrojan.Win32.Genus.DID
SymantecSMG.Heur!gen
ESET-NOD32Win32/TrojanDownloader.Agent.PTT
APEXMalicious
TrendMicro-HouseCallBKDR_SIMBOT.SMJQ
AvastWin32:Simbot-A [Trj]
ClamAVWin.Trojan.Kazy-6838217-0
KasperskyHEUR:Trojan.Win32.Miancha.gen
BitDefenderGen:Variant.Downloader.19
NANO-AntivirusTrojan.Win32.Small.bzqcm
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
TencentTrojan.Win32.Miancha.za
SophosTroj/DwnLdr-MDK
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.27746
ZillyaTrojan.InjectGen.Win32.7
TrendMicroBKDR_SIMBOT.SMJQ
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4befd56d22727acb
EmsisoftGen:Variant.Downloader.19 (B)
IkarusTrojan-Downloader.Win32.Small
JiangminTrojanDownloader.Small.akan
VaristW32/Rubin.A.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Downloader]/Win32.Rubinurd.bf
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Injector.ARA!MTB
XcitiumTrojWare.Win32.Injector.ccu@4zdswy
ArcabitTrojan.Downloader.19
ViRobotTrojan.Win32.Downloader.32768.PI
ZoneAlarmHEUR:Trojan.Win32.Miancha.gen
GDataWin32.Trojan.PSE1.13MYFBD
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R885
Acronissuspicious
BitDefenderThetaAI:Packer.4CC1459B1F
ALYacGen:Variant.Downloader.19
TACHYONTrojan-Downloader/W32.Small.32768.FW
VBA32TrojanDownloader.Rubinurd
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
ZonerTrojan.JS.31147
RisingTrojan.Injector!1.A7C6 (CLASSIC)
YandexTrojan.GenAsa!GIDBK2aXaUc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Downloader.Rubinurd.bf
FortinetW32/Injector.BFSU!tr
AVGWin32:Simbot-A [Trj]
Cybereasonmalicious.d22727
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Agent.19c7aff9

How to remove Downloader.19?

Downloader.19 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment