Trojan

Trojan-Downloader.Win32.Tovkater.bou (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Tovkater.bou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.bou virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
inactiveanimals.top
duckandbear.top

How to determine Trojan-Downloader.Win32.Tovkater.bou?


File Info:

crc32: AAB9D93C
md5: 94bd0bb572637af3568f9e550fa1642c
name: 94BD0BB572637AF3568F9E550FA1642C.mlw
sha1: e48dfe6268f73286997a1c15c1409872661629c5
sha256: 1a7c0da4042007d19399a96b93476dd9c5bbb484669aa3b8c7bb42ddfbd141c0
sha512: 1b6825249c58f35f8b822aa231cb3247ed999139004b5cca47c776bff163df7e5e83c94e7f726f7ea72afd607db44fd70820a69f5445e6f39eb05c40aa725f4f
ssdeep: 3072:AND7V2BCDm6Ltzu0pDes/8Wnroukw07Pt6UZT/X0J3KQsp82nYKBQ/qUFRm63CkJ:Ar2R6xj18Wnrouk1Tt6ULO/25eFEkGFG
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: oGrimm Stone Prod. All rights reserved.
InternalName: myGrimm Installer
FileVersion: 12.8.2.9
CompanyName:
Comments: xInstall software
ProductName: iNSIS installer
ProductVersion: 21.8.2.9
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.bou also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0051921e1 )
LionicTrojan.Win32.Tovkater.a!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2400
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37516782
CylanceUnsafe
ZillyaAdware.DLBoost.Win32.3351
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Tovkater.ef5e0d3f
K7GWTrojan-Downloader ( 0051921e1 )
Cybereasonmalicious.572637
CyrenW32/Taterf.A!Generic
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6664559-0
KasperskyTrojan-Downloader.Win32.Tovkater.bou
BitDefenderTrojan.GenericKD.37516782
NANO-AntivirusTrojan.Win32.Tovkater.etrahp
MicroWorld-eScanTrojan.GenericKD.37516782
TencentWin32.Trojan-downloader.Tovkater.Huft
Ad-AwareTrojan.GenericKD.37516782
SophosGeneric ML PUA (PUA)
ComodoMalware@#1vi36pe92hoff
BitDefenderThetaGen:NN.ZexaF.34170.jmKfaWlCMjoG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.94bd0bb572637af3
EmsisoftTrojan.GenericKD.37516782 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Tovkater.ai
AviraHEUR/AGEN.1117983
Antiy-AVLTrojan/Generic.ASMalwS.310C58A
MicrosoftTrojan:Win32/Ditertag.A
SUPERAntiSpywareAdware.Generic/Variant
GDataTrojan.GenericKD.37516782
AhnLab-V3Downloader/Win32.Tovkater.R210632
Acronissuspicious
McAfeeArtemis!94BD0BB57263
MAXmalware (ai score=99)
VBA32Trojan.Wacatac
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
YandexTrojan.DL.Tovkater!MhEfGkGs7eU
FortinetW32/Tovkater.FQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Tovkater.bou?

Trojan-Downloader.Win32.Tovkater.bou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment