Trojan

Trojan.Downloader.Aspack information

Malware Removal

The Trojan.Downloader.Aspack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.Aspack virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

api.xp666.com
download.xp666.com

How to determine Trojan.Downloader.Aspack?


File Info:

crc32: 0E23E9FC
md5: 05910d20d384eed3d174e1bb4221bcd4
name: xqws2345_29258.exe
sha1: 11e6ffde9ee5117b9b0c8bb7f2f5bd3bc46367ea
sha256: dd2eca021fa24de7c5045e2be53d05db9f77117487765a330b3b8edebe6d2164
sha512: 1453e15924abcfeee91903e3311e4f19e88e1b860c1b2d4480965c5d44b631f7569ad171bfed03a87b7fc7a9ff8006fb39d75f6467403f919d1b4c98b6a17be5
ssdeep: 49152:UWdudf6D6d3D84Xt88hTKgWJU5d5pEZuJT/OPEuV/eaFIlfzUtBfSOtmGfWcMgi:/sdt344XmK5djEZuJ/OPR/7sfWugnyC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.3.4.131
OriginalFilename: steup.exe
ProductVersion: 3.3
Translation: 0x0804 0x03a8

Trojan.Downloader.Aspack also known as:

MicroWorld-eScanGen:Variant.Symmi.79626
ALYacGen:Variant.Symmi.79626
CylanceUnsafe
BitDefenderGen:Variant.Symmi.79626
Cybereasonmalicious.0d384e
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Symmi.79626
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Symmi.79626 (B)
Trapminemalicious.high.ml.score
FireEyeGen:Variant.Symmi.79626
MAXmalware (ai score=87)
ArcabitTrojan.Symmi.D1370A
VBA32TScope.Trojan.Delf
Ad-AwareGen:Variant.Symmi.79626
MalwarebytesTrojan.Downloader.Aspack
ESET-NOD32a variant of Win32/Duote.A
RisingMalware.Heuristic!ET#76% (RDMK:cmRtazqkOuKJH5ZS0U8samW9bcUt)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Doute.A!tr
BitDefenderThetaGen:NN.ZexaF.34106.z70baOBN!Fgi
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan.Downloader.Aspack?

Trojan.Downloader.Aspack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment