Trojan

About “Trojan.Downloader.Pusrac.A” infection

Malware Removal

The Trojan.Downloader.Pusrac.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.Pusrac.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Downloader.Pusrac.A?


File Info:

name: EBB56DB1E5E2141FA8B0.mlw
path: /opt/CAPEv2/storage/binaries/9b7ea620fea83209978ef33c8733e0128bed79cfdacd14c1ee06f5e437d6848b
crc32: ADC75ECB
md5: ebb56db1e5e2141fa8b0b1f2983a0884
sha1: b07f8d7f6203162f9268eda2fbc5187742e4ea9f
sha256: 9b7ea620fea83209978ef33c8733e0128bed79cfdacd14c1ee06f5e437d6848b
sha512: dde24606593c2494ec31f16b02f6d0f5046e98360aaf23819a592269d21cedfd591a88e7776aba221497b5d3a63382335e35e7904db600d85375c14dff6e8792
ssdeep: 768:YylqP9QLBOwC9yHk16c0aiUxkJ9sd6wkh4IYJ92b48ZwoqxDSL4oKKjd78x:PlqP9QLBKh0aLybvqxmscox
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149236B43F6E14475F0649EFC6C29A6D5FE3B3DB12C29644863AD0F4E8EA43915C0836B
sha3_384: 25d70751b94e2f3525ba8512d75a75055ac3935c9bd811909fdc397cae12f61e5ed680ff9259dcac697bbc238f4c27ce
ep_bytes: 558becb9070000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Downloader.Pusrac.A also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.ArchSMS.lcHl
DrWebTrojan.DownLoad.1154
MicroWorld-eScanTrojan.Downloader.Pusrac.A
FireEyeGeneric.mg.ebb56db1e5e2141f
McAfeeGenDownloader.en
CylanceUnsafe
ZillyaBackdoor.CPEX.Win32.35135
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:Win32/Dadobra.ae82cd8b
Cybereasonmalicious.1e5e21
ArcabitTrojan.Downloader.Pusrac.A
BitDefenderThetaAI:Packer.6241F2A61E
CyrenW32/Delfloader.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Dadobra.NDX
APEXMalicious
TrendMicro-HouseCallTROJ_DLOADR.SMI
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Downloader.Pusrac.A
NANO-AntivirusTrojan.Win32.Agent.cvprpm
AvastWin32:Malware-gen
TencentWin32.Trojan.Dldr.Qnkl
Ad-AwareTrojan.Downloader.Pusrac.A
EmsisoftTrojan.Downloader.Pusrac.A (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
VIPRETrojan.Downloader.Pusrac.A
TrendMicroTROJ_DLOADR.SMI
McAfee-GW-EditionGenDownloader.en
Trapminemalicious.high.ml.score
SophosMal/DelpDldr-C
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.aabw
GoogleDetected
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=94)
Antiy-AVLTrojan/Generic.ASMalwS.13
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Downloader.Pusrac.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.C74325
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen
ALYacTrojan.Downloader.Pusrac.A
MalwarebytesMalware.Heuristic.1006
RisingTrojan.Vigorf!8.EAEA (TFE:4:05PXx6Ns2TJ)
YandexTrojan.GenAsa!dOxH1pUOgGM
IkarusTrojan-Downloader.Win32.Delf.gxe
MaxSecureTrojan.Malware.74839192.susgen
FortinetW32/Dadobra.C!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Downloader.Pusrac.A?

Trojan.Downloader.Pusrac.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment