Trojan

What is “TrojanDownloader:Win32/Dontovo.A”?

Malware Removal

The TrojanDownloader:Win32/Dontovo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dontovo.A virus can do?

  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Dontovo.A?


File Info:

name: 04C497337C81115D7D5D.mlw
path: /opt/CAPEv2/storage/binaries/db506a7344f40c4137d26d13001f811fe35d5dbe4a2036547f231207bcf6ae4e
crc32: 6F6D4073
md5: 04c497337c81115d7d5df32ebc6458d1
sha1: 637bf9cb044a221be20771122ece3600ddca0fb2
sha256: db506a7344f40c4137d26d13001f811fe35d5dbe4a2036547f231207bcf6ae4e
sha512: a8d72b84e59243924aadf859552289bd7cf0bb103dab27d82896e55ca502e4570896e3ccd89c5f6b86b082c5974e7dc962b875d0ce865fc1cfeab4edaab617c6
ssdeep: 384:eTFCB6dIl+80GKaa9AXIxUPf4x3/hTZk67JoyZ:oUBJl+80ValTPk3pD9o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D039E02ED7C50B3F1CA263B80E6103AD2F9D7F3A2429502D8895D63BC6F7E95819D57
sha3_384: 25d0a5a8ad70b71f640a7c3cdb5e98a6de064c99840a90af0adf6514390aac73cddb9bba87de65b2c1ab211daa864293
ep_bytes: e9250000000000e9001c0046bdc0005d
timestamp: 2008-01-22 01:48:39

Version Info:

0: [No Data]

TrojanDownloader:Win32/Dontovo.A also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Katusha.lnDk
MicroWorld-eScanTrojan.Agent.EDXF
ClamAVWin.Downloader.68082-1
FireEyeGeneric.mg.04c497337c81115d
CAT-QuickHealTrojan.KatushaCS.S20170282
McAfeeGeneric Dropper.ahy
Cylanceunsafe
VIPRETrojan.Agent.EDXF
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000011 )
AlibabaTrojanDownloader:Win32/Katusha.f4ac1a0a
K7GWTrojan ( 700000011 )
Cybereasonmalicious.b044a2
VirITTrojan.Win32.Crypt.BEZ
CyrenW32/Trojan.EQJM-7381
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.OPF
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Katusha.a
BitDefenderTrojan.Agent.EDXF
NANO-AntivirusTrojan.Win32.FraudLoad.jeyo
AvastWin32:Ups [Cryp]
TencentMalware.Win32.Gencirc.10b270b5
TACHYONTrojan-Downloader/W32.FraudLoad.40960.H
EmsisoftTrojan.Agent.EDXF (B)
F-SecureTrojan.TR/Dldr.FrdLoad.veiw
DrWebTrojan.Packed.1414
ZillyaDownloader.Agent.Win32.375055
TrendMicroTROJ_DLOAD.RON
McAfee-GW-EditionBehavesLike.Win32.Virut.pz
Trapminesuspicious.low.ml.score
SophosMal/EncPk-CZ
IkarusTrojan-Downloader.Win32.FraudLoad
GDataTrojan.Agent.EDXF
JiangminTrojanDownloader.FraudLoad.cxt
AviraTR/Dldr.FrdLoad.veiw
Antiy-AVLTrojan[Packed]/Win32.Katusha
XcitiumTrojWare.Win32.PkdKrap.AG@1naz70
ArcabitTrojan.Agent.EDXF
ViRobotTrojan.Win32.Downloader.40960.HA
ZoneAlarmPacked.Win32.Katusha.a
MicrosoftTrojanDownloader:Win32/Dontovo.A
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R9405
BitDefenderThetaAI:Packer.DDE4D8B71E
ALYacTrojan.Agent.EDXF
MAXmalware (ai score=100)
VBA32BScope.Trojan-Downloader.FraudLoad
MalwarebytesMachineLearning/Anomalous.96%
PandaSpyware/Virtumonde
TrendMicro-HouseCallTROJ_DLOAD.RON
RisingTrojan.DL.Win32.FraudLoad.bjc (CLASSIC)
YandexTrojan.GenAsa!AM5NKBPjv98
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CodecPack.ENJ!tr.dldr
AVGWin32:Ups [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Dontovo.A?

TrojanDownloader:Win32/Dontovo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment