Trojan

Trojan-Downloader.Win32.Tovkater.wnj removal tips

Malware Removal

The Trojan-Downloader.Win32.Tovkater.wnj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Tovkater.wnj virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Behavior consistent with a dropper attempting to download the next stage.
  • Anomalous binary characteristics

Related domains:

shadeunit.club
strangerthingz.club

How to determine Trojan-Downloader.Win32.Tovkater.wnj?


File Info:

crc32: BCEC3EE4
md5: c71955cb6c9a7df2cf76ce1c432841cb
name: C71955CB6C9A7DF2CF76CE1C432841CB.mlw
sha1: 67d155cb2e62cb958069dfd9d3fb351e5982de52
sha256: cb77c0636e1fd5cef57390eff9098d4240611ab8f545ee8025d0d06b850157d2
sha512: 564401397c4a8633db61fe5eaa7c8339e85832231d71f5ffc01eb923352aff0ee292d5a0266a552889555ad444ffb37366f93e936c917251685d955ba880c367
ssdeep: 3072:SrV1c41Utsu7pKUy4wJs2Tt984EUXXGuIwMlw+DcpvrXHG8o:So4UzliJ04lT0Rcdm8o
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: veer iRoadProds 12 All rights reserved.
InternalName: bnon Content Installer 32
FileVersion: 5.17.21.39
CompanyName:
Comments: janx Install software 16
ProductName: plik NSIS 32 installer bonx
ProductVersion: 5.17.21.39
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Tovkater.wnj also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Tovkater-6651892-0
FireEyeGeneric.mg.c71955cb6c9a7df2
CAT-QuickHealTrojandownloader.Tovkater
McAfeeArtemis!C71955CB6C9A
CylanceUnsafe
ZillyaDownloader.Tovkater.Win32.550
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 0051ae7b1 )
BitDefenderGen:Variant.Bulz.301016
K7GWTrojan-Downloader ( 0051ae7b1 )
Cybereasonmalicious.b6c9a7
CyrenW32/Tovkater.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Tovkater.wnj
AlibabaTrojanDownloader:Win32/Tovkater.30c864a6
NANO-AntivirusTrojan.Win32.Tovkater.eutihs
MicroWorld-eScanGen:Variant.Bulz.301016
Ad-AwareGen:Variant.Bulz.301016
EmsisoftGen:Variant.Bulz.301016 (B)
ComodoApplication.Win32.InstallMonster.DX@7e9j3l
F-SecureTrojan.TR/Tovkater.jaioq
DrWebTrojan.InstallMonster.2408
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GLM20
McAfee-GW-EditionBehavesLike.Win32.Downloader.cc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
AviraHEUR/AGEN.1117983
MAXmalware (ai score=97)
Antiy-AVLTrojan[Downloader]/Win32.Tovkater
KingsoftWin32.TrojDownloader.Tovkater.al.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Bulz.D497D8
ZoneAlarmTrojan-Downloader.Win32.Tovkater.wnj
GDataGen:Variant.Bulz.301016
AhnLab-V3Downloader/Win32.Tovkater.R350556
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.iy0@a0wgTgci
ALYacGen:Variant.Bulz.301016
VBA32TrojanDownloader.Tovkater
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0GLM20
RisingDownloader.Tovkater!8.E5CE (CLOUD)
YandexTrojan.DL.Tovkater!4KwZb1YK8L8
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Tovkater.GI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Downloader.845

How to remove Trojan-Downloader.Win32.Tovkater.wnj?

Trojan-Downloader.Win32.Tovkater.wnj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment