Trojan

What is “TrojanDownloader:Win32/Gendwnurl!rfn”?

Malware Removal

The TrojanDownloader:Win32/Gendwnurl!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Gendwnurl!rfn virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine TrojanDownloader:Win32/Gendwnurl!rfn?


File Info:

crc32: B101EF05
md5: 262e5f3fce2d2434269547064a5aac77
name: 262E5F3FCE2D2434269547064A5AAC77.mlw
sha1: f8bd45f4137904875a4f910f5c235b43f2c0b1ba
sha256: dd2aac18262405a0c50ba9f2e0178ade395727d54f6d0b585a21445076193f22
sha512: 56da9dc4c1ac0cfd5de1cebac22a2bc354cb7b0ff4a6a2f0a6a7b9f45d018f2abe95e8e39ce94ccaf1a9ac72ae14a9d2f6a7324e668e75bb8a63fdad618f2e97
ssdeep: 24576:GNr/j9doieUwBIw9hzPSon54kLYQxOXmEzvyL+jXF:GV/hOAwBT9hLSS+GYQvqB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1984-2016 Adobe Systems Incorporated and its licensors. All rights reserved.
InternalName: Adobe Acrobat Reader DX
FileVersion: 10.7.20033.13755
ProductName: Adobe Acrobat Reader DX
ProductVersion: 10.7.20033.13755
FileDescription: Adobe Acrobat Reader DX
OriginalFilename: AcroRd32.exe
Translation: 0x0409 0x04e4

TrojanDownloader:Win32/Gendwnurl!rfn also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.62972
MicroWorld-eScanGen:Variant.Jacard.13238
FireEyeGeneric.mg.262e5f3fce2d2434
Qihoo-360Win32/Trojan.f18
McAfeeGenericRXAA-AA!262E5F3FCE2D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Rakhni.a!c
K7AntiVirusTrojan-Downloader ( 004e02ad1 )
BitDefenderGen:Variant.Jacard.13238
K7GWTrojan-Downloader ( 004e02ad1 )
Cybereasonmalicious.fce2d2
BitDefenderThetaAI:Packer.E19542C118
CyrenW32/Trojan.CTUT-7366
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Delf.eikp
NANO-AntivirusTrojan.Win32.Delf.eneujh
TencentMalware.Win32.Gencirc.10b3c9a9
Ad-AwareGen:Variant.Jacard.13238
SophosMal/Generic-S
F-SecureTrojan.TR/Downloader.Gen7
ZillyaDownloader.Rakhni.Win32.234
TrendMicroHT_RAKHNI_GD0700BE.UVPM
McAfee-GW-EditionGenericRXBD-FT!668388863EC3
EmsisoftGen:Variant.Jacard.13238 (B)
SentinelOneStatic AI – Malicious PE – Installer
JiangminTrojanDownloader.Rakhni.fa
AviraTR/Downloader.Gen7
Antiy-AVLTrojan/Win32.Bcex
MicrosoftTrojanDownloader:Win32/Gendwnurl!rfn
ArcabitTrojan.Jacard.D33B6
ZoneAlarmTrojan.Win32.Delf.eikp
GDataGen:Variant.Jacard.13238
CynetMalicious (score: 85)
AhnLab-V3Downloader/Win32.Delf.C1783347
VBA32TrojanDownloader.Rakhni
ALYacGen:Variant.Jacard.13238
MAXmalware (ai score=80)
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CBO
TrendMicro-HouseCallHT_RAKHNI_GD0700BE.UVPM
RisingDownloader.Gendwnurl!8.D8D6 (TFE:4:PEeXeVwoyzG)
YandexTrojan.GenAsa!VhAlGrfMo8k
IkarusTrojan-Downloader.Win32.Rakhni
eGambitUnsafe.AI_Score_86%
FortinetW32/Dloader.CDW!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Gendwnurl!rfn?

TrojanDownloader:Win32/Gendwnurl!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment