Trojan

What is “Trojan.Downloader.S3376907”?

Malware Removal

The Trojan.Downloader.S3376907 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.S3376907 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

csdw.sinosteelinvest.com
www.sinosteelinvest.com
dwonload.sinosteelinvest.com

How to determine Trojan.Downloader.S3376907?


File Info:

crc32: 14CC0EE2
md5: 137dbeefbb3fa5aca00a299c19370042
name: 137DBEEFBB3FA5ACA00A299C19370042.mlw
sha1: 0214115fdb1a11f006a396d681a8b94f0b7b132e
sha256: 1a0e9878c3d11da02f96dca25df802a38beb282aaf45e24b9a27e2b2f63b88c3
sha512: 2fe3edcaefb112791fd940ec3fdd579426d23c4fbdda3b367f442f5a528e5e4803fa70a260b35c844a135c1cc809aa94f50ffc62170a4e8cb7eee3e4308c3b9a
ssdeep: 49152:r+Fn0raYu8cpo2ZIeSo7fP1uACFI8WQeK4+X:ZraYu7o2O/oEwrQL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Downloader.S3376907 also known as:

K7AntiVirusAdware ( 0053d2191 )
Elasticmalicious (high confidence)
DrWebAdware.Softcnapp.92
ClamAVWin.Malware.Softcnapp-6787524-0
CAT-QuickHealTrojan.Downloader.S3376907
ALYacGen:Variant.Application.Bundler.196
CylanceUnsafe
ZillyaTool.Bundler.Win32.28492
SangforTrojan.Win32.Save.a
K7GWAdware ( 0053d2191 )
Cybereasonmalicious.fbb3fa
CyrenW32/Softcnapp.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Bundler.196
NANO-AntivirusTrojan.Win32.Softcnapp.fhrcuu
MicroWorld-eScanGen:Variant.Application.Bundler.196
TencentTrojan.Win32.Generic.e
Ad-AwareGen:Variant.Application.Bundler.196
SophosSoftcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.M@7xrf2d
BitDefenderThetaGen:NN.ZexaF.34236.CAW@a8uob7jj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.137dbeefbb3fa5ac
EmsisoftGen:Variant.Application.Bundler.196 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.aeahd
AviraHEUR/AGEN.1120142
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28011F9
MicrosoftTrojan:Win32/Adload!rfn
GDataGen:Variant.Application.Bundler.196
AhnLab-V3Adware/Win32.AdLoad.R235056
Acronissuspicious
McAfeeGenericRXGI-CM!137DBEEFBB3F
MAXmalware (ai score=100)
VBA32Trojan.Skeeyah
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA22 (CLASSIC)
YandexTrojan.GenAsa!Sm6Jj9a+TE4
IkarusTrojan-Downloader.Win32.Adload
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenericRXGI.CM!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Trojan.Downloader.S3376907?

Trojan.Downloader.S3376907 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment