Trojan

Trojan-Downloader.Win32.Satacom.la information

Malware Removal

The Trojan-Downloader.Win32.Satacom.la is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Satacom.la virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk

How to determine Trojan-Downloader.Win32.Satacom.la?


File Info:

name: E118B0362A3FB69467AE.mlw
path: /opt/CAPEv2/storage/binaries/5d29a6dc3611bb72f5e7fa719b12c69be166bc3affd0721ae2f8eae27f140650
crc32: 18977333
md5: e118b0362a3fb69467ae6ce9c5e1f3e3
sha1: 33915bcda4ab38233e7ff2b5f89ea06092f76bb2
sha256: 5d29a6dc3611bb72f5e7fa719b12c69be166bc3affd0721ae2f8eae27f140650
sha512: d1ae3bda420a27de8a25d09a9f8327b9427aa4a9e551639e88aab756b48b3e6af8a3ae04d057f7f2139d38090d32f89e82ccb814f83903399f4c12e6e62c965c
ssdeep: 24576:t7FUDowAyrTVE3U5FmtWbAHrMH5fvVdSKoyTu3QMSmVv5x7awFhJdNo69lOy7KTn:tBuZrEUx6MbgKRTudSAv55DdN7POGjq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A5D03FF268A13EC56E1B3205B39220997BBE61681A8C1E47FC344DCF765601E3B656
sha3_384: 56bd4394bde13d62c4fd9654dfa4406d5f5a9d9390bef3f9f14a4a61a19c88657de2b11df49f743cea79146611f94791
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: instaaleer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: instaaleer
ProductVersion: 100.102.02
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Satacom.la also known as:

MicroWorld-eScanGen:Variant.Zusy.435211
ClamAVWin.Malware.Zusy-9962926-0
FireEyeGen:Variant.Zusy.435211
McAfeeArtemis!E118B0362A3F
VIPREGen:Variant.Zusy.435211
K7AntiVirusTrojan ( 00596a771 )
K7GWTrojan ( 00596a771 )
CyrenW32/Kryptik.HGW.gen!Eldorado
SymantecTrojan.Gen.9
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GenKryptik.FYMJ
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Satacom.la
BitDefenderGen:Variant.Zusy.435211
NANO-AntivirusTrojan.Win32.Satacom.jrlgvm
AvastWin32:Trojan-gen
McAfee-GW-EditionBehavesLike.Win32.DStudio.vc
EmsisoftGen:Variant.Zusy.435211 (B)
AviraHEUR/AGEN.1251348
MAXmalware (ai score=88)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan-Stealer.TinyNuke.WW7II5
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R510475
ALYacGen:Variant.Zusy.435211
VBA32TrojanDownloader.Satacom
MalwarebytesMalware.AI.4210109497
RisingTrojan.Generic@AI.96 (RDML:Dtj8o7UoihKranO3blrpiA)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FYMJ!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Satacom.la?

Trojan-Downloader.Win32.Satacom.la removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment