Trojan

Trojan.Downloader.ERR (file analysis)

Malware Removal

The Trojan.Downloader.ERR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.ERR virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan.Downloader.ERR?


File Info:

name: D7267DA297BFC2F767AA.mlw
path: /opt/CAPEv2/storage/binaries/3c5a61f8829568cddd7f687354ab2b9f9ba4024e95a6ec01f61197f3a4439ae0
crc32: 1F65A54A
md5: d7267da297bfc2f767aafd64eff7a1d9
sha1: ae481e31f275c3f21c6294de8d78e267d04557c0
sha256: 3c5a61f8829568cddd7f687354ab2b9f9ba4024e95a6ec01f61197f3a4439ae0
sha512: 93368744a27b234936a111ec6d4599d3546391b1c5d6ec5d19c281d02a1ea69d50707dd64bdcfcc1817353e366fddefc881007858fbce551b27e4dc6c6cf0b60
ssdeep: 96:s/elwj2R+xxqCmybIAQFsmjKGWRdbX4mzPZt79xZL8M8h24IKjGUmcmqCJQPhzVu:Kg28AyyRL9xZYWmlhzV/t2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14612E704B7E94331F9BF8B39BC7346105676FA538A33CF0D58D9A24A1A323944A15FA2
sha3_384: 215e217bdd638e42dd8c50c1430f3cecabf65e7b26faeb43cecdb81ef9a3c19427bb2d9847b7fd1338b2335fab3f8008
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-05-08 02:18:41

Version Info:

Translation: 0x0000 0x04b0
Comments: cluldccx44o
CompanyName: 54545y50i4w
FileDescription: myiy5g1bxca
FileVersion: 4.5.2.2
InternalName: nha3l2ogwaf.exe
LegalCopyright: 0jnexbzvc2a
OriginalFilename: nha3l2ogwaf.exe
ProductName: myiy5g1bxca
ProductVersion: 4.5.2.2
Assembly Version: 4.5.2.2

Trojan.Downloader.ERR also known as:

LionicWorm.MSIL.Guap.q!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.15083
MicroWorld-eScanGen:Trojan.Mardom.MN.11
FireEyeGeneric.mg.d7267da297bfc2f7
CAT-QuickHealWorm.MsilFC.S9417149
McAfeeArtemis!D7267DA297BF
CylanceUnsafe
ZillyaDownloader.Agent.Win32.400672
SangforWorm.MSIL.Guap.gen
K7AntiVirusTrojan-Downloader ( 0054b2571 )
AlibabaWorm:MSIL/MalwareX.a1e7337e
K7GWTrojan-Downloader ( 0054b2571 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilF.34084.am0@aKeUhqb
CyrenW32/SmallTrojan.BV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FKM
Paloaltogeneric.ml
ClamAVWin.Packed.Azorult-7436406-1
KasperskyHEUR:IM-Worm.MSIL.Guap.gen
BitDefenderGen:Trojan.Mardom.MN.11
NANO-AntivirusTrojan.Win32.Razy.hgiduq
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan-downloader.Agent.Wpsw
Ad-AwareGen:Trojan.Mardom.MN.11
SophosMal/Generic-S
ComodoMalware@#lfp7nw9mcnau
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
EmsisoftGen:Trojan.Mardom.MN.11 (B)
IkarusTrojan-Downloader.MSIL.Agent
GDataGen:Trojan.Mardom.MN.11
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.2FEDADD
MicrosoftTrojan:Win32/AgentTesla!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C3995718
VBA32TScope.Trojan.MSIL
ALYacGen:Trojan.Mardom.MN.11
MalwarebytesTrojan.Downloader.ERR
APEXMalicious
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.FKM!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.297bfc
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.74035307.susgen

How to remove Trojan.Downloader.ERR?

Trojan.Downloader.ERR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment