Trojan

TrojanDownloader:Win32/Horst.R malicious file

Malware Removal

The TrojanDownloader:Win32/Horst.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Horst.R virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Horst.R?


File Info:

name: 8AEE6580D7626B9389E8.mlw
path: /opt/CAPEv2/storage/binaries/efe1928c8f69122f71574206749d037d08dce77fa4920abb3596e3cceb8cc0ce
crc32: E3C4DB3E
md5: 8aee6580d7626b9389e83558b0916b15
sha1: 1f9a084cfe8d7cc9b326f2a81b4a94d05f578b4e
sha256: efe1928c8f69122f71574206749d037d08dce77fa4920abb3596e3cceb8cc0ce
sha512: c26cb12ef6881be0894902a1ef41bf4c694fa9c385b1f2e661433cfe14144c1e8564457a7475c1991b61a2b3e645e403b5cd1a3467b2becb438be7d00b7bf157
ssdeep: 768:AOXF7QyE8NTTEqlF6smlvW4hbeRtmVUKHgxf0wLx/tol9EGW:AGciTJlUdI4hCRtCgXLRm9W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB538D7339C2C47BC49285B114F98B46AB77761217B5C9D3AB9C159E6F322D0AE3E302
sha3_384: 5c898d8f1d4ff603b32a8ae6e948514dcd152c05f46fb97b6615aaf77503a4dd0f23274cd43b703c00c057575d44edc8
ep_bytes: 6a606800894000e881030000bf940000
timestamp: 2009-01-18 13:38:29

Version Info:

0: [No Data]

TrojanDownloader:Win32/Horst.R also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebTrojan.DownLoad.28087
MicroWorld-eScanTrojan.Downloader.JKVV
FireEyeGeneric.mg.8aee6580d7626b93
CAT-QuickHealDownloader.Calac.13420
ALYacTrojan.Downloader.JKVV
CylanceUnsafe
SangforARMADILLO17
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34638.dqY@aeDgNtj
CyrenW32/S-3395e203!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.ORX
APEXMalicious
KasperskyTrojan-Downloader.Win32.Calac.bar
BitDefenderTrojan.Downloader.JKVV
NANO-AntivirusTrojan.Win32.Calac.bxqng
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Calac.Eeru
Ad-AwareTrojan.Downloader.JKVV
EmsisoftTrojan.Downloader.JKVV (B)
ComodoTrojWare.Win32.TrojanDownloader.Colac.~AA@2m7iv
BaiduWin32.Trojan-Downloader.Agent.ch
TrendMicroTROJ_HORST.SMI
McAfee-GW-EditionBehavesLike.Win32.Generic.kt
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Horst
GDataTrojan.Downloader.JKVV
JiangminTrojanDownloader.Calac.aj
AviraTR/Downloader.Gen
ViRobotTrojan.Win32.A.Downloader.56256
MicrosoftTrojanDownloader:Win32/Horst.R
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.RL_Calac.R284022
McAfeeDownloader-BNE
MAXmalware (ai score=86)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesMalware.AI.4033305061
TrendMicro-HouseCallTROJ_HORST.SMI
RisingTrojan.Generic@AI.100 (RDMK:cmRtazo825Uuou/vPX426xk6bphm)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Horst.H!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/DNSChanger.NY

How to remove TrojanDownloader:Win32/Horst.R?

TrojanDownloader:Win32/Horst.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment