Trojan

TrojanDownloader:Win32/Dluca removal instruction

Malware Removal

The TrojanDownloader:Win32/Dluca is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dluca virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Dluca?


File Info:

name: F799BB707E18FC3A5903.mlw
path: /opt/CAPEv2/storage/binaries/23208ff1cfca8062e2eedfcc2377de3d70247a818df36ca1291e4906d4231409
crc32: 650251D8
md5: f799bb707e18fc3a590315ae80f8ecb6
sha1: f6f397b3075903172fbcd0c7685ebe5703225ce6
sha256: 23208ff1cfca8062e2eedfcc2377de3d70247a818df36ca1291e4906d4231409
sha512: c1709980adc35b3ec5cb408aa197ccc20554279cd89577f4e9f93bdcd0051ebf6978e723eb65e13dcdfdc6fcc19b88efbc07faed8b53d22cd5ff1897325da114
ssdeep: 768:gaefR9FNksC3NECucHFaNrVlVnKgLvGcgmcTgf7MRnLH2KRHTP4i7:DwlasQN/ucoxDlJLvGjgoxDJTA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C03E14077C0CE5AD04D4B36D253A6150747FD20CE2A7B3AA381652DACAFB948FD4722
sha3_384: 6876e9e47c96ccf288b6a96462ec66b32ecebdcb4f9a300fe3ea7fc966fc755173b60514191ec61a9793fd8e8fa58679
ep_bytes: b8788541005064ff3500000000648925
timestamp: 2004-10-20 14:03:30

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 1, 0, 0, 23
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 1, 0, 0, 23
SpecialBuild:
Translation: 0x0c09 0x04b0

TrojanDownloader:Win32/Dluca also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PornoAsset.tpVd
DrWebTrojan.DownLoader.895
MicroWorld-eScanGen:Variant.Barys.90535
FireEyeGeneric.mg.f799bb707e18fc3a
CAT-QuickHealTrojan.MauvaiseRI.S5265011
SkyhighBehavesLike.Win32.Dropper.nc
McAfeeDownloader-DC.a
Cylanceunsafe
VIPREGen:Variant.Barys.90535
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Barys.90535
K7GWTrojan-Downloader ( 005323e81 )
K7AntiVirusTrojan-Downloader ( 005323e81 )
BitDefenderThetaAI:Packer.325A17D41F
VirITTrojan.Win32.Dluca.C
SymantecAdware.SafeSearch
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Dluca.NAF
APEXMalicious
ClamAVWin.Downloader.Dluca-41
KasperskyTrojan-Ransom.Win32.PornoAsset.cwmo
AlibabaRansom:Win32/PornoAsset.945976fe
NANO-AntivirusTrojan.Win32.PornoAsset.fgvqzh
ViRobotTrojan.Win32.Downloader.39424
RisingDownloader.Dluca!8.136A (TFE:5:yXNCP5GyTbJ)
SophosML/PE-A
GoogleDetected
F-SecureTrojan.TR/Downloader.Gen
BaiduWin32.Trojan-Downloader.Agent.ap
TrendMicroTROJ_DLUCA.BC
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.90535 (B)
IkarusTrojan-Downloader.Win32.Dluca
GDataGen:Variant.Barys.90535
JiangminTrojanDownlaoder.Dluca.ag
WebrootW32.Malware.Gen
VaristW32/Dlucadl.RODZ-5986
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Dluca
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Dluca.NAF@2moi
ArcabitTrojan.Barys.D161A7
ZoneAlarmTrojan-Ransom.Win32.PornoAsset.cwmo
MicrosoftTrojanDownloader:Win32/Dluca
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dluca.R5616
ALYacGen:Variant.Barys.90535
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Agent
MalwarebytesDluca.Trojan.Downloader.DDS
PandaSpyware/Dluca
TrendMicro-HouseCallTROJ_DLUCA.BC
TencentTrojan.Win32.DL.Dluca.a
YandexTrojan.GenAsa!3bSp2mZUAN0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.979092.susgen
FortinetW32/Dluca.AH!tr
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.307590
AvastWin32:Adware-gen [Adw]

How to remove TrojanDownloader:Win32/Dluca?

TrojanDownloader:Win32/Dluca removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment