Trojan

TrojanDownloader:MSIL/Gendwnurl!rfn (file analysis)

Malware Removal

The TrojanDownloader:MSIL/Gendwnurl!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:MSIL/Gendwnurl!rfn virus can do?

  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

ranking3web.com

How to determine TrojanDownloader:MSIL/Gendwnurl!rfn?


File Info:

crc32: 401C2117
md5: a8329ac4c37a88166b54436d54e5c0ad
name: A8329AC4C37A88166B54436D54E5C0AD.mlw
sha1: 0f6fcee6f9513c67ad3e0799e29fc07207d65db6
sha256: dd8327dbfda5681d9442414bc8d16f00c4abd0fe79e0749bab21d3be7afc95b7
sha512: 90ae2789881793fa975d7a5c1b50683f77703adaff25f2c3ab91779b48e4219a3167952d2e6ebaf82116dda77969c00db2c7ea71d53d490d4312eedf7b13f8fc
ssdeep: 384:KEoeCV/GlEKVZtNTUzLNs98pVyALMaj1KD:QxV/0EKVXi1s92eaj
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: hhc.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: hhc.exe

TrojanDownloader:MSIL/Gendwnurl!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.23569
CAT-QuickHealTrojan.GenericFC.S17875353
McAfeeTrojan-FKFP!A8329AC4C37A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004f1c4b1 )
BitDefenderGen:Variant.Cerbu.23569
K7GWTrojan-Downloader ( 004f1c4b1 )
Cybereasonmalicious.4c37a8
CyrenW32/S-23853127!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Siggen6.ezggec
Ad-AwareGen:Variant.Cerbu.23569
EmsisoftGen:Variant.Cerbu.23569 (B)
ComodoMalware@#3u695pa98dvyk
DrWebTrojan.Siggen6.63994
ZillyaDownloader.Small.Win32.94676
TrendMicroHT_SMALL_GA3107DA.UVPM
McAfee-GW-EditionTrojan-FKFP!A8329AC4C37A
FireEyeGeneric.mg.a8329ac4c37a8816
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Small
AviraHEUR/AGEN.1129526
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojanDownloader:MSIL/Gendwnurl!rfn
ArcabitTrojan.Cerbu.D5C11
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Cerbu.23569
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Small.R187245
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Cerbu.23569
MalwarebytesMalware.AI.23557314
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.ASE
TrendMicro-HouseCallHT_SMALL_GA3107DA.UVPM
RisingDownloader.Small!8.B41 (TFE:C:f69uJMxaYIT)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Small.ASE!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34804.bm0@amPPBCm
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.a9e

How to remove TrojanDownloader:MSIL/Gendwnurl!rfn?

TrojanDownloader:MSIL/Gendwnurl!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment