Trojan

How to remove “Trojan-Downloader.Win32.Tovkater.a”?

Malware Removal

The Trojan-Downloader.Win32.Tovkater.a is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.a virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Anomalous binary characteristics

Related domains:

sciencemiracle.top
duckandbear.top

How to determine Trojan-Downloader.Win32.Tovkater.a?


File Info:

crc32: 071C77D7
md5: 4ed2754406416e6f3f40431d29055bed
name: 4ED2754406416E6F3F40431D29055BED.mlw
sha1: f26bad18a75186534c35e5570281fd715bed4555
sha256: de8b6952a64442b6b56687d72aadfa65b5a23e5bd5e50ebb3b677694d31b87dd
sha512: 8d9aa4fd715fb19993e471dca274bdb89d393aa862fd7f5b253a35b7c6b86b67b8ba1e1f203ba987eb76b4fe9ab8b6c48430bb75bf39accb36fd66068f317cd8
ssdeep: 6144:ko4U6Q3RLSfy83qGQ/+aHUED6MSSxEVoctJh+O:iQhLQLDQ/+M7DhnldO
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: ColdCreekProd. All rights reserved.
InternalName: ColdCreekInstaller
FileVersion: 3.1.0.1
CompanyName: ColdCreekProd
Comments: Files installer
ProductName: Free files installer
ProductVersion: 3.1.0.1
FileDescription: Free files installer
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.a also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.GenericKD.12473781
FireEyeGeneric.mg.4ed2754406416e6f
CAT-QuickHealTrojandownloader.Tovkater
McAfeeArtemis!4ED275440641
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 00518e881 )
BitDefenderDropped:Trojan.GenericKD.12473781
K7GWTrojan-Downloader ( 00518e881 )
Cybereasonmalicious.406416
CyrenW32/Tovkater.S.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6651874-0
KasperskyTrojan-Downloader.Win32.Tovkater.a
NANO-AntivirusTrojan.Win32.Tovkater.etoaeb
TencentWin32.Trojan-downloader.Tovkater.Piak
Ad-AwareDropped:Trojan.GenericKD.12473781
EmsisoftApplication.Downloader (A)
ComodoApplication.Win32.InstallMonster.DX@7e9j3l
F-SecureTrojan.TR/Tovkater.faqrh
DrWebTrojan.InstallMonster.2399
TrendMicroTROJ_GEN.R011C0PJC20
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
GDataDropped:Trojan.GenericKD.12473781
AviraHEUR/AGEN.1117983
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/Win32.Tovkater
ArcabitTrojan.Generic.DBE55B5
SUPERAntiSpywareAdware.InstallMonster/Variant
ZoneAlarmHEUR:Trojan-Downloader.Win32.Tovkater.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R209982
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.hyW@a4jhNWfi
ALYacDropped:Trojan.GenericKD.12473781
VBA32TrojanDownloader.Tovkater
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDownloader.Tovkater.EX
TrendMicro-HouseCallTROJ_GEN.R011C0PJC20
YandexTrojan.DL.Tovkater!KcYoe/d37Tk
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Tovkater.A!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Tovkater.a?

Trojan-Downloader.Win32.Tovkater.a removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment