Trojan

TrojanDownloader.GCleaner (file analysis)

Malware Removal

The TrojanDownloader.GCleaner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader.GCleaner virus can do?

  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDownloader.GCleaner?


File Info:

name: E7EB0A55E60D0ED1E649.mlw
path: /opt/CAPEv2/storage/binaries/9a28c1692b32b79747a375fe3409f19e8bbe2481fdfbf0be1750f36767d4991f
crc32: 11E19D41
md5: e7eb0a55e60d0ed1e6495cbd96b6627e
sha1: 718723a2585703f3077fd0c5b1d1c27dfd55718d
sha256: 9a28c1692b32b79747a375fe3409f19e8bbe2481fdfbf0be1750f36767d4991f
sha512: 3d427281735415aa43e7a67ce1a0ec76c7b197ec8012f92e59f5bb4fc908a4d9e56350f5ae30d84a2b0cf7318bbdab6a73b72e1aef6a06d1e33b81ce367c18d3
ssdeep: 6144:QUi6ZnL6U55CBxBgRsOXnzjbctQfWoxVgw8+6KAOFQQeZ:Ni6ZnuU55CBxBgRrXnz/e3KDQ5Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164348E1075A2C472E57210760978DBB6453EB9310B6196EBB3D44F7ECF302D2AA31E6B
sha3_384: 7b5791722f2eda3939a5301ac850b3d619e0f0ecb9391b32fd0ffecece523a220a85e91b20c6e8cdea4060f736339f9b
ep_bytes: e8bd050000e97afeffff8b4df464890d
timestamp: 2022-04-06 21:13:42

Version Info:

0: [No Data]

TrojanDownloader.GCleaner also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Zusy.426563
FireEyeGeneric.mg.e7eb0a55e60d0ed1
CAT-QuickHealPUA.GcleanerPMF.S28244869
ALYacGen:Variant.Zusy.426563
CylanceUnsafe
VIPREGen:Variant.Zusy.426563
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005480a41 )
K7GWTrojan-Downloader ( 005480a41 )
Cybereasonmalicious.5e60d0
CyrenW32/Agent.EPA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.ELB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.GCleaner.gen
BitDefenderGen:Variant.Zusy.426563
NANO-AntivirusTrojan.Win32.GCleaner.jpaaii
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10d065e8
Ad-AwareGen:Variant.Zusy.426563
EmsisoftGen:Variant.Zusy.426563 (B)
DrWebTrojan.Siggen17.58603
ZillyaDownloader.Agent.Win32.471055
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.GleaDow.A
JiangminTrojanDownloader.GCleaner.r
AviraHEUR/AGEN.1250671
Antiy-AVLTrojan/Generic.ASMalwS.7F84
ArcabitTrojan.Zusy.D68243
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C5120832
Acronissuspicious
McAfeeGenericRXTH-PG!E7EB0A55E60D
MAXmalware (ai score=86)
VBA32TrojanDownloader.GCleaner
MalwarebytesTrojan.Downloader
RisingStealer.Tepfer!8.13357 (TFE:5:HIbdI5elbGO)
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.165313645.susgen
FortinetW32/Agent.ELB!tr.dldr
BitDefenderThetaAI:Packer.3192077F1F
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove TrojanDownloader.GCleaner?

TrojanDownloader.GCleaner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment