Trojan

About “Trojan-Downloader.Win32.Tovkater.kdc” infection

Malware Removal

The Trojan-Downloader.Win32.Tovkater.kdc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.kdc virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
chubbyoasis.top
borrowme.top

How to determine Trojan-Downloader.Win32.Tovkater.kdc?


File Info:

crc32: C52D3483
md5: 2bf7252127109bfbff9c1985d5fa48dd
name: 2BF7252127109BFBFF9C1985D5FA48DD.mlw
sha1: f1c805585a80ca861f475f9bc090ba03e4b3b3dd
sha256: 033fc0f497b3bee8277c4184ff9269b504a111dc83e645468e99557dc7ec49ad
sha512: 97ac6a0c7347914c1b8f4bdadf520c81eeb54ddbbad9a6f6f040778506f44414cd16b97c5389a2a1fdbd305728acb9df41d967adffb0d025bf8f7b8b30788fee
ssdeep: 3072:lND7V2BCDm6LtzuhpR+ngmgUq43miYIhJ1mwYlN95rCkGTh5r64qU96:lr2R6xKRcBgUp1clN32kGF5r64q5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: mms iStoneProd 2 All rights reserved.
InternalName: xx3l Content Installer 8
FileVersion: 12.84.3.9
CompanyName:
Comments: mlm Install software 24
ProductName: nlp NSIS 32 installer
ProductVersion: 2.8.2.3
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.kdc also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0051a2ea1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2399
CynetMalicious (score: 100)
CAT-QuickHealPUA.MauvaiseRI.S5255025
ALYacGen:Variant.Bulz.603126
CylanceUnsafe
ZillyaDownloader.Tovkater.Win32.515
SangforTrojan.Win32.Tovkater.FO
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0051a2ea1 )
Cybereasonmalicious.85a80c
CyrenW32/Tovkater.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6646882-0
KasperskyTrojan-Downloader.Win32.Tovkater.kdc
BitDefenderGen:Variant.Bulz.603126
NANO-AntivirusTrojan.Win32.Tovkater.eukegv
MicroWorld-eScanGen:Variant.Bulz.603126
TencentWin32.Trojan-downloader.Tovkater.Hvtn
Ad-AwareGen:Variant.Bulz.603126
SophosML/PE-A
ComodoApplication.Win32.InstallMonster.DX@7e9j3l
BitDefenderThetaGen:NN.ZexaF.34294.hy0@amicarpG
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_HPGen-32
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.2bf7252127109bfb
EmsisoftGen:Variant.Bulz.603126 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Tovkater.ai
AviraHEUR/AGEN.1117983
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.33EB218
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Bulz.D933F6
GDataGen:Variant.Bulz.603126
AhnLab-V3Trojan/Win32.Abnores.R213690
Acronissuspicious
McAfeeArtemis!2BF725212710
MAXmalware (ai score=95)
VBA32Trojan.Wacatac
MalwarebytesMalware.AI.4191415631
PandaTrj/Genetic.gen
TrendMicro-HouseCallPossible_HPGen-32
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!HQ2cLI777p0
FortinetW32/Tovkater.FU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Tovkater.kdc?

Trojan-Downloader.Win32.Tovkater.kdc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment