Malware

Generic.GC.Downloader.4935590C information

Malware Removal

The Generic.GC.Downloader.4935590C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.GC.Downloader.4935590C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings

How to determine Generic.GC.Downloader.4935590C?


File Info:

name: 29E7B4B6CCBCFD7A09B0.mlw
path: /opt/CAPEv2/storage/binaries/d3e25eac45fbe545058197cbb6a61879444a7a51bd0358a50e2eb89b3280d13f
crc32: BE90F11D
md5: 29e7b4b6ccbcfd7a09b0a905c89a62c3
sha1: 71211244329c06d395d1af792d103ca9349fd736
sha256: d3e25eac45fbe545058197cbb6a61879444a7a51bd0358a50e2eb89b3280d13f
sha512: 184dd01f013715d0ce8ec20248f986815af4917fd8ed23b9e2bf42e8d126968e52c934aba93c1395a0d82f609cd2b072fb85eaa38778ebf8a863f41e863a0ac8
ssdeep: 3072:zNIy4qbLqrVticc4eqVmpPI6i+f/YSqkLoG8fv9PeuzCTzLfdk8eoQYANBn:zd4rc4eAmpPI6OSTIfvLCTFk8eJYANBn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0C37D11B5C0C032E5B729315970EBB19ABDF8300E546DDF63981ABA1E306C19A39E7B
sha3_384: c9fa822c1d1106413a4810451262602fe2ea4ecf4ff4a6a28c96454d34056911d44ecc7b308b47ec1d3e4a493ae9f13b
ep_bytes: e8c5030000e97afeffff558bec6a00ff
timestamp: 2021-12-02 23:14:45

Version Info:

0: [No Data]

Generic.GC.Downloader.4935590C also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.GC.Downloader.4935590C
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00569c731 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 00569c731 )
Cybereasonmalicious.6ccbcf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Phorpiex.X
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderGeneric.GC.Downloader.4935590C
AvastWin32:WormX-gen [Wrm]
TencentWin32.Trojan.Generic.Hupz
Ad-AwareGeneric.GC.Downloader.4935590C
SophosMal/Generic-S
DrWebTrojan.Siggen15.60840
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.29e7b4b6ccbcfd7a
EmsisoftGeneric.GC.Downloader.4935590C (B)
IkarusWorm.Win32.Phorpiex
GDataGeneric.GC.Downloader.4935590C
JiangminTrojanDownloader.Generic.blqb
eGambitUnsafe.AI_Score_98%
AviraWORM/Phorpiex.fykgs
GridinsoftRansom.Win32.Sabsik.sa
ArcabitGeneric.GC.Downloader.D4B4FA6C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.Generic.C4817712
BitDefenderThetaAI:Packer.F979A6D41E
ALYacGeneric.GC.Downloader.4935590C
MAXmalware (ai score=88)
MalwarebytesMalware.AI.743426854
TrendMicro-HouseCallTROJ_GEN.R002H0CL521
RisingWorm.Phorpiex!1.B6EF (CLASSIC)
YandexWorm.Phorpiex!cNcUVBCfwh8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/NtRootKit.1786!tr
AVGWin32:WormX-gen [Wrm]
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Generic.GC.Downloader.4935590C?

Generic.GC.Downloader.4935590C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment