Trojan

Trojan-Downloader.Win32.Alien.tgt removal instruction

Malware Removal

The Trojan-Downloader.Win32.Alien.tgt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Alien.tgt virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • A HTTP/S link was seen in a script or command line
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-Downloader.Win32.Alien.tgt?


File Info:

name: E68981AAFF99133D513F.mlw
path: /opt/CAPEv2/storage/binaries/dd771b3d419f9f0ab105bf10a5475ee43ef30d7da024a58d7a3b4a3d775cb635
crc32: 56DB99D5
md5: e68981aaff99133d513f3c1b377c3dd8
sha1: f5940e82c4f36accf4568f64afd6f088314f3cc1
sha256: dd771b3d419f9f0ab105bf10a5475ee43ef30d7da024a58d7a3b4a3d775cb635
sha512: 59f7a28ed087c896e3555eab96c158282d8c00c0c77712093b8e6daa156895e784108b51c633304b158a85ffe1ff0270e24f68494add33a2997647ce6c986441
ssdeep: 49152:pmh+CFEAf1km/SjidwxdxR9aulLYIIAzoBASVMdawva6Y:ppCFEuem/e/xuulL5IVKdlaj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB9533DC3BCCE663DEC29A7488765FB0D46E93915016470F7B0030BBB9269A1AD5E732
sha3_384: 2187836f78c617e0dfab9799516339f62555963e991301a41fa4dcb631b23b350fa54c4dc00bc12f7b9135418aae6bc9
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:43

Version Info:

CompanyName: 小南瓜
FileDescription: 显卡驱动升级助手
FileVersion: 1.0.1.3
LegalCopyright: Copyright © 2023 小南瓜 All Rights Reserved
ProductName: Gpu Driver Update Tool
Translation: 0x0804 0x04b0

Trojan-Downloader.Win32.Alien.tgt also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Alien.a!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.e68981aaff99133d
SkyhighBehavesLike.Win32.Dropper.tc
McAfeeArtemis!E68981AAFF99
Cylanceunsafe
SangforDownloader.Win32.Alien.V0yz
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDownloader:Win32/Alien.3284641b
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecTrojan.Gen.MBT
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Alien.tgt
AvastNSIS:TrojanX-gen [Trj]
TencentWin32.Trojan-Downloader.Alien.Imnw
F-SecureTrojan.TR/Dldr.Agent.bltid
TrendMicroTROJ_FRS.VSNTB224
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
AviraTR/Dldr.Agent.bltid
KingsoftWin32.Troj.Undef.a
ZoneAlarmTrojan-Downloader.Win32.Alien.tgt
GDataWin32.Trojan-Downloader.Generic.VSKEIR
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_FRS.VSNTB224
AVGNSIS:TrojanX-gen [Trj]
Cybereasonmalicious.2c4f36
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.Alien.tgt?

Trojan-Downloader.Win32.Alien.tgt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment