Malware

Generic.GC.Downloader.2A9F4CBF removal instruction

Malware Removal

The Generic.GC.Downloader.2A9F4CBF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.GC.Downloader.2A9F4CBF virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • CAPE detected the Phorpiex malware family
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Generic.GC.Downloader.2A9F4CBF?


File Info:

name: 7E8537E9B73E6AE3292A.mlw
path: /opt/CAPEv2/storage/binaries/17f72364b1f0b17fa3db3a88d2857d2713ab4e395709b951cc13794b96f2043f
crc32: D2B44A64
md5: 7e8537e9b73e6ae3292a3eb44c756175
sha1: 68a7197eaee16c50b1debe5c53d284468524440a
sha256: 17f72364b1f0b17fa3db3a88d2857d2713ab4e395709b951cc13794b96f2043f
sha512: b14a8e233a32654d5fa35083bd38ad40525aae82fc779a8d7241e7281e1cdd95d69e0995966f2722fa100ae8dc09487de6a3053c90c8112874ae17e1a5cb2d7c
ssdeep: 384:siamFLltaS+2lYM1y3v6lzUqZCg1qR10UO87/qs3Vw:7lIT8Oed9k0UN753V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BA21858BBA90311F9B5097479B0853E807A7DF23F8284CFE7814C8A1574781E67AF2B
sha3_384: aea7174868ac06f55fa261a54f5a92b3f6de966add5fee75d84349134afa2abb852eb4aa2291d286439dfc3953ce1dbe
ep_bytes: 558bec6aff682057400068a033400064
timestamp: 2020-07-24 10:46:32

Version Info:

0: [No Data]

Generic.GC.Downloader.2A9F4CBF also known as:

BkavW32.FamVT.BalojazJ.Trojan
LionicTrojan.Win32.Reconyc.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.GC.Downloader.2A9F4CBF
FireEyeGeneric.mg.7e8537e9b73e6ae3
McAfeeGenericRXLV-PT!7E8537E9B73E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGeneric.GC.Downloader.2A9F4CBF
K7GWTrojan ( 0053af931 )
K7AntiVirusTrojan ( 0053af931 )
BitDefenderThetaGen:NN.ZexaF.34182.buW@a8BRBXbi
CyrenW32/Phorpiex.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Phorpiex.V
TrendMicro-HouseCallMal_DLDER
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Reconyc.vho
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Reconyc.hpbguw
RisingWorm.Phorpiex!1.CA88 (CLOUD)
EmsisoftGeneric.GC.Downloader.2A9F4CBF (B)
DrWebTrojan.Siggen9.61309
ZillyaWorm.Phorpiex.Win32.1716
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Reconyc.aspn
AviraTR/Downloader.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.30C2334
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojanDownloader:Win32/Phorpiex.GS!MTB
GDataGeneric.GC.Downloader.2A9F4CBF
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2544633
VBA32BScope.TrojanBanker.CliptoShuffler
ALYacGeneric.GC.Downloader.2A9F4CBF
MalwarebytesTrojan.TLDR
PandaTrj/GdSda.A
TencentWin32.Trojan.Reconyc.Akzd
YandexWorm.Phorpiex!oeWjCFaV7MA
IkarusWorm.Win32.Phorpiex
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Phorpiex.V!worm
AVGWin32:CoinminerX-gen [Trj]
AvastWin32:CoinminerX-gen [Trj]

How to remove Generic.GC.Downloader.2A9F4CBF?

Generic.GC.Downloader.2A9F4CBF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment