Trojan

Trojan-Downloader.Win32.AddUser removal tips

Malware Removal

The Trojan-Downloader.Win32.AddUser is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.AddUser virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Downloader.Win32.AddUser?


File Info:

name: 8C33EA229C098D3CE918.mlw
path: /opt/CAPEv2/storage/binaries/fa5b313bc6b80ab85aa1890dddeffc24ae5e3bb92524fde9bc577ed14ae33296
crc32: D145AA40
md5: 8c33ea229c098d3ce9185df51709d194
sha1: b51d4afe8c0e15bbf7accddc7f3ddb8fea5e4603
sha256: fa5b313bc6b80ab85aa1890dddeffc24ae5e3bb92524fde9bc577ed14ae33296
sha512: 5c2593e3e7e07b9e38e89db3b92900f51d98bcb1191fd6650843a7c8cbe230395b8b9382c361b58473316f0cadd6a24a25d02d5abf44d96abb2dacb31b53a76d
ssdeep: 49152:9HSp4+Dk/bX5W61uw8b/uuC0gWtd+A8kvFnkT8pfzaFn05Ricx4PHzLb3vnfs4tu:5Ck/bX5H2b/ue8kvu4pfzaFn05Ricx4Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198C5BE05F111C0B2C5A21630CC67F3F78A285E05CA33A7D757EBFD1B79BA6A35A25188
sha3_384: 62c1a74953755058aaeaa5981b47bed98c585267769d924131abe282a1ce172d0f3c7e970d1258d1a2cccd69348c918d
ep_bytes: 558bec6aff68303d570068d444490064
timestamp: 2022-10-22 06:52:56

Version Info:

FileVersion: 10.15.0.0
FileDescription: 小精灵游戏安全盾
ProductName: 小精灵
ProductVersion: 10.15.0.0
LegalCopyright: 本程序仅供学习娱乐,禁止商业用途,否则后果自负
Comments: 仅供娱乐
Translation: 0x0804 0x04b0

Trojan-Downloader.Win32.AddUser also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
FireEyeGeneric.mg.8c33ea229c098d3c
McAfeePUP-XEY-DN
Cylanceunsafe
ZillyaDownloader.AddUser.Win32.31
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojanDownloader:Win32/AddUser.54ca7cdd
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36348.Js0@a4frVDpb
CyrenW32/S-965fe2e2!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.AddUser.gen
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.1179e1ad
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.moderate.ml.score
IkarusTrojan.Win32
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftPUA:Win32/SuspiciousProcStarter
ZoneAlarmHEUR:Trojan-Downloader.Win32.AddUser.gen
GDataWin32.Trojan.PSE.1KQMTX4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Evo-gen.C5287406
MalwarebytesGeneric.Malware.AI.DDS
RisingDownloader.AddUser!8.12CAD (TFE:5:3u9jSpzaZGP)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.29c098
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.AddUser?

Trojan-Downloader.Win32.AddUser removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment