Trojan

About “TrojanDownloader:Win32/Seimon.D” infection

Malware Removal

The TrojanDownloader:Win32/Seimon.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Seimon.D virus can do?

  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Seimon.D?


File Info:

name: 86D76672D21C8E042EAC.mlw
path: /opt/CAPEv2/storage/binaries/689a3bbfdd98ee7b1b183dd4f46c278664d797b111401ebf14b67f07930083a3
crc32: AB66038B
md5: 86d76672d21c8e042eac66fc50f0dfda
sha1: 2dcffab31503eb1a0f801b4c332a9b164935bb4d
sha256: 689a3bbfdd98ee7b1b183dd4f46c278664d797b111401ebf14b67f07930083a3
sha512: 8cdcb7bb1525349565ad46fe2aaea992761707e3664a458335887d6bbd7294653634e7a78815579eead3817de3be1206b305d30bbdacbe3ff6d2d44062b677a1
ssdeep: 3072:qyuCb8p4P7+MT/GHeigYoYlFExtXCc/aLxEnXyBs:qyuLA6k/pYeYEnCC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15604BF35324383F3D62045B039B52BF2F5F7E463AA2116FB97D04E1C8EFA18588699C9
sha3_384: a9d5dfdefe94ae10d7c19916a28fec7bf913e197f0cf1211e0024def62b5a3ca37713b395d3c6ef0eb26ce9b4573394c
ep_bytes: e954d3ffff0b623ae0d7159ead42427d
timestamp: 2008-12-27 02:39:16

Version Info:

CompanyName:
FileDescription: ShortCutGen MFC 응용 프로그램
FileVersion: 1, 0, 0, 1
InternalName: ShortCutGen
LegalCopyright: Copyright (C) 2006
LegalTrademarks:
OriginalFilename: ShortCutGen.EXE
ProductName: ShortCutGen 응용 프로그램
ProductVersion: 1, 0, 0, 1
Translation: 0x0412 0x04b0

TrojanDownloader:Win32/Seimon.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Seimon.a!c
AVGWin32:Crypt-DZY [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad.45080
MicroWorld-eScanGen:Adware.Heur.ly0@c5ztN0bG
FireEyeGeneric.mg.86d76672d21c8e04
SkyhighBehavesLike.Win32.PWSGoft.ch
McAfeeDownloader-BKG
Cylanceunsafe
ZillyaTrojan.Katusha.Win32.26538
SangforSuspicious.Win32.Save.ins
K7AntiVirusHacktool ( 005288361 )
AlibabaTrojanDownloader:Win32/Seimon.7f89fd73
K7GWHacktool ( 005288361 )
BitDefenderThetaAI:Packer.F02C90FE1D
Paloaltogeneric.ml
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Agent.OPQ
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Crypt-DZY [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.ILovlan.gen
BitDefenderGen:Adware.Heur.ly0@c5ztN0bG
TencentMalware.Win32.Gencirc.13ff2969
EmsisoftGen:Adware.Heur.ly0@c5ztN0bG (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Adware.Heur.ly0@c5ztN0bG
TrendMicroPossible_DLDR
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Seimon
JiangminTrojanDownloader.Agent.dyul
GoogleDetected
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.TrojDownloader.MnlessT.hu.200704
MicrosoftTrojanDownloader:Win32/Seimon.D
XcitiumTrojWare.Win32.TrojanDownloader.Agent.BKG1@10jhd2
ArcabitAdware.Heur.E4D47F
ZoneAlarmHEUR:Trojan-Downloader.Win32.ILovlan.gen
GDataGen:Adware.Heur.ly0@c5ztN0bG
VaristW32/SCG.A.gen!Eldorado
AhnLab-V3Trojan/Win32.Downloader.C60392
ALYacGen:Adware.Heur.ly0@c5ztN0bG
TACHYONTrojan/W32.Agent.182272.M
VBA32BScope.Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Downloader.XAT
TrendMicro-HouseCallPossible_DLDR
RisingTrojan.DL.Win32.Mnless.des (CLASSIC)
YandexTrojan.Seimon.Gen
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.73884519.susgen
FortinetW32/Dloader.BKG!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/ILovlan.gen

How to remove TrojanDownloader:Win32/Seimon.D?

TrojanDownloader:Win32/Seimon.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment