Trojan

Trojan-Downloader.Win32.Tovkater.cche malicious file

Malware Removal

The Trojan-Downloader.Win32.Tovkater.cche is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.cche virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan-Downloader.Win32.Tovkater.cche?


File Info:

name: 7BDE2327A4648BD8D8A6.mlw
path: /opt/CAPEv2/storage/binaries/3d281d982d165126bd323b937713e9bf778749bad2689ea11f79ca1ec7403cbb
crc32: 2BA8E85A
md5: 7bde2327a4648bd8d8a6d4428156d653
sha1: f66632af377ad8ca0850e34f90268f5f9a935ec3
sha256: 3d281d982d165126bd323b937713e9bf778749bad2689ea11f79ca1ec7403cbb
sha512: ecce7200c38b5557b834e92f2de4c5d642ae083fe571abf8513972c24ec275a8c2cf243136295bb2c950eb036f32b4b1bc86a7fa87ca6d14cc68e90249344593
ssdeep: 6144:So4UQCWoQjuvyC/UZwB8to0u7+gtJr1N96Wm/3X/0KN1Bgc3XRH2l:6boQSvyO8tI+Ij6//p6EBWl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B6412065371C03BEAB30D31153AE981ADB969C134558727B703DBEDBEA33C1CA5E992
sha3_384: f5a4dd0af17cc5d5a9934e59a7e90b7f346b2484e3fde514c31776d24c2aefc3eacfd4b2f83d690a96cb4a9a037d2ef6
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2017-08-01 00:35:01

Version Info:

Comments: jdtukyiuk tt nertumr tttttttttthdtyhertg q jfjjftyuklyilyuktyuklyiljftyuklyilv b s g xInstalls software 32
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.cche also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22814140
ClamAVWin.Dropper.Tovkater-6646864-0
FireEyeGeneric.mg.7bde2327a4648bd8
ALYacTrojan.Generic.22814140
MalwarebytesTovkater.Trojan.Downloader.DDS
VIPRETrojan.Generic.22814140
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 00520c311 )
AlibabaMalware:Win32/km_2c3f9.None
K7GWTrojan-Downloader ( 00520c311 )
Cybereasonmalicious.7a4648
ArcabitTrojan.Generic.D15C1DBC
BitDefenderThetaAI:Packer.FB10057E21
CyrenW32/Tovkater.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Tovkater.IC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Tovkater.cche
BitDefenderTrojan.Generic.22814140
NANO-AntivirusRiskware.Win32.InstMonster.ewnofw
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan-Downloader.Tovkater.Qgil
EmsisoftTrojan.Generic.22814140 (B)
F-SecureHeuristic.HEUR/AGEN.1353053
DrWebTrojan.DownLoader26.9530
McAfee-GW-EditionBehavesLike.Win32.Fake.fc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1333305
MAXmalware (ai score=98)
Antiy-AVLTrojan/Win32.BTSGeneric
XcitiumTrojWare.Win32.TrojanDownloader.Tovkater.IC@7g83bp
MicrosoftProgram:Win32/Multiverze
SUPERAntiSpywareTrojan.Agent/Gen-Tovkater
ZoneAlarmTrojan-Downloader.Win32.Tovkater.cche
GDataNSIS.Trojan-Downloader.Tovkater.C
GoogleDetected
AhnLab-V3PUP/Win.Installer.R562197
Acronissuspicious
McAfeeArtemis!7BDE2327A464
VBA32TrojanDownloader.Tovkater
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Tovkater/NSIS!1.AF36 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Tovkater.IA!tr.dldr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Tovkater.cche?

Trojan-Downloader.Win32.Tovkater.cche removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment