Malware

Generic.GC.Downloader.27D297F2 removal guide

Malware Removal

The Generic.GC.Downloader.27D297F2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.GC.Downloader.27D297F2 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Generic.GC.Downloader.27D297F2?


File Info:

name: A0039FBC46F2E874F2E4.mlw
path: /opt/CAPEv2/storage/binaries/0c8a145ef290f597e21906ad6b5e5e7aeee460a65f11543f1a04a1a0d9286d10
crc32: B35B893F
md5: a0039fbc46f2e874f2e4151712993343
sha1: 1fe1ef6bdd0b011d5778207a2481178c4ec748f1
sha256: 0c8a145ef290f597e21906ad6b5e5e7aeee460a65f11543f1a04a1a0d9286d10
sha512: 21d201e2bed5f5bc9cb75f57798dfc566c7a09eb32e606dae00d0a9e66c1a179447e7ffa7a2ca3f734e301b62c744928661310016b50f963d683d432a266797b
ssdeep: 768:Inu3jL7I9H/k+aI+G0au3+Z5vBhdpppppppppppppppppppppppppppppppppppH:Inu3jL7I9H/k+j+mW+P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D444345E61E160468EE7764F247BF19AFF78D1306DDECC1D9CC194A6AEA882C72108F
sha3_384: d02c7390ddfaaf23b6040621d7e6b50ff4796425a256daeae4de81107f516a7b70e8684463be7707cdc3523891ea6bd3
ep_bytes: 558bec6aff68403f400068382f400064
timestamp: 2019-04-24 03:13:51

Version Info:

0: [No Data]

Generic.GC.Downloader.27D297F2 also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Shodi.lzG3
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Agent.Phorpiex
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGeneric.GC.Downloader.27D297F2
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Genome.I.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Phorpiex.S
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Phorpiex.a
AlibabaTrojanDropper:Win32/Phorpiex.7fdc66eb
NANO-AntivirusTrojan.Win32.Phorpiex.gjhxba
MicroWorld-eScanGeneric.GC.Downloader.27D297F2
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.116a85b1
Ad-AwareGeneric.GC.Downloader.27D297F2
ComodoTrojWare.Win32.Phorpiex.CT@803ooe
ZillyaWorm.Phorpiex.Win32.1086
TrendMicroTROJ_GEN.R002C0WG821
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
FireEyeGeneric.mg.a0039fbc46f2e874
EmsisoftGeneric.GC.Downloader.27D297F2 (B)
SentinelOneStatic AI – Malicious PE
GDataGeneric.GC.Downloader.27D297F2
JiangminTrojanDropper.Phorpiex.a
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.2B57C09
ArcabitGeneric.GC.Downloader.27D297F2
MicrosoftTrojan:Win32/Occamy.C0C
AhnLab-V3Malware/Win32.RL_Generic.R277920
Acronissuspicious
McAfeeGenericRXAA-FA!A0039FBC46F2
VBA32suspected of Trojan.Downloader.gen
TrendMicro-HouseCallTROJ_GEN.R002C0WG821
RisingSpammer.Agent!1.B7D9 (CLASSIC)
YandexTrojan.GenAsa!uE2V2EBLvDk
IkarusWorm.Win32.Phorpiex
eGambitUnsafe.AI_Score_91%
FortinetW32/Phorpiex.S!worm
BitDefenderThetaGen:NN.ZexaF.34062.quZ@aas2bMhi
AVGWin32:Malware-gen
Cybereasonmalicious.c46f2e
MaxSecureTrojan.Malware.1728101.susgen

How to remove Generic.GC.Downloader.27D297F2?

Generic.GC.Downloader.27D297F2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment