Trojan

Trojan.DownloadAssistant.Generic malicious file

Malware Removal

The Trojan.DownloadAssistant.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DownloadAssistant.Generic virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.DownloadAssistant.Generic?


File Info:

name: D33861463EEF53AFDD89.mlw
path: /opt/CAPEv2/storage/binaries/7f176be5d018183e8dc0ce71e458d1ad3a4eb3f22a868f79848fa920f1f4c10e
crc32: 0CAF1C37
md5: d33861463eef53afdd89c8f3a8a05fe8
sha1: 2e2c2a42b23ac92e3bb99e259c3e4cb712178928
sha256: 7f176be5d018183e8dc0ce71e458d1ad3a4eb3f22a868f79848fa920f1f4c10e
sha512: 8af378109c1a27a97c1b7a3fdb9c8b6d2937bde1b6b4b3b63e2c8a12f8440c041252974619377e7c5a6ed32ed3f865117323391f1a5bf70dc2bb012780b54aa4
ssdeep: 98304:oGgdaNnnnRVNmjfJW4N66Lyq/jU/ON6SXFIAlE:odKnPoW4NHLV/j+ON5XFIAu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EF5334DB57DF9B4D02599B88B14723B0EE29ABF1BB4241429E439496EF7C87012D33B
sha3_384: 43bfe42241ce6b04c9225b3945121111f44f6ceb96ca4f8fbf00152a78280bd8279f0f66e4efe9f48789ade83abd0ace
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-27 20:55:33

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: TVLand Setup
FileVersion:
LegalCopyright:
ProductName: TVLand
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.DownloadAssistant.Generic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34410551
FireEyeTrojan.Generic.34410551
SkyhighBehavesLike.Win32.PUPInstaller.wc
ALYacTrojan.Generic.34410551
Cylanceunsafe
ZillyaTrojan.Injuke.Win32.37799
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Injuke.2e123930
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 99)
BitDefenderTrojan.Generic.34410551
TencentWin32.Trojan.Injuke.Cujl
EmsisoftTrojan.Generic.34410551 (B)
F-SecureHeuristic.HEUR/AGEN.1332256
DrWebTrojan.Siggen22.18433
VIPRETrojan.Generic.34410551
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Ekstak.ciey
AviraHEUR/AGEN.1332256
KingsoftWin32.Trojan.Injuke.gen
ArcabitTrojan.Generic.D20D1037
ZoneAlarmUDS:Trojan.Win32.Injuke.gen
AhnLab-V3Trojan/Win.DownloadAssistant.R621621
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
MalwarebytesTrojan.DownloadAssistant.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0XL523
FortinetW32/Agent.SLC!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.DownloadAssistant.Generic?

Trojan.DownloadAssistant.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment