Trojan

TrojanDownloader:Win32/Sinresby!pz information

Malware Removal

The TrojanDownloader:Win32/Sinresby!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Sinresby!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Sinresby!pz?


File Info:

name: 88718D8C584D34626431.mlw
path: /opt/CAPEv2/storage/binaries/7ede19ad8bfef2a8f6347e3d8131f419e1e36744e4c6518891ff29b5af7c1702
crc32: C1E41EE9
md5: 88718d8c584d34626431ecf1db2146ae
sha1: e179127b60fb4697e95ad1cbabf265de82c93d99
sha256: 7ede19ad8bfef2a8f6347e3d8131f419e1e36744e4c6518891ff29b5af7c1702
sha512: 1285fcfae2f65d1c48577a9f5253cfe90d8833257068927db256db2d5449ad13f103cf9c531fdf1edddece393817dea3bfe2449e66b8f550f089884daa5bc590
ssdeep: 196608:uXlNay8qoyAjyUZHhgJYEFVts+Nn1xXfhZI3ZZ2FdamxJ6DJdoj7fyCoCmOTKQJR:S3OyAjyUNwp1V83ZZ2TsDCYOT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149A63356401664F5F9827C30A63EF9E1AD427C236E4A35300C47FAE8A9779D3E6C2B07
sha3_384: ac27490e3ecc0b3a0262794b230828496f88655e314385cb9c2426ffadff7677fc5220794c041f8d447f0db7bfd6fec9
ep_bytes: 60be006057008dbe00b0e8ff5783cdff
timestamp: 2023-07-27 07:04:54

Version Info:

FileVersion: 1.0.0.0
FileDescription: 青春版下载器
ProductName: 青春版下载器
ProductVersion: 1.0.0.0
CompanyName: 青春版下载器
LegalCopyright: 青春版下载器 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

TrojanDownloader:Win32/Sinresby!pz also known as:

CyrenCloudW32/Trojan.CLL.gen!Eldorado
BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.482936
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.88718d8c584d3462
SkyhighBehavesLike.Win32.Generic.tc
ALYacGen:Variant.Zusy.482936
MalwarebytesTrojan.MalPack.FlyStudio
VIPREGen:Variant.Zusy.482936
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005071f51 )
AlibabaTrojanDownloader:Win32/Injuke.06de3f87
K7GWAdware ( 005071f51 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D75E78
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Injuke.hsvy
BitDefenderGen:Variant.Zusy.482936
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf1286
Ad-AwareGen:Variant.Zusy.482936
EmsisoftGen:Variant.Zusy.482936 (B)
F-SecureHeuristic.HEUR/AGEN.1370128
ZillyaTrojan.Bsymem.Win32.4900
TrendMicroTROJ_GEN.R002C0DL723
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injuke.sjp
GoogleDetected
AviraHEUR/AGEN.1370128
MAXmalware (ai score=100)
Antiy-AVLTrojan[Packed]/Win32.FlyStudio
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojanDownloader:Win32/Sinresby!pz
ViRobotTrojan.Win.Z.Zusy.9489920.R
ZoneAlarmTrojan.Win32.Injuke.hsvy
GDataWin32.Trojan.PSE.15MID6N
VaristW32/Trojan.CLL.gen!Eldorado
AhnLab-V3Downloader/Win.Sinresby.R581331
McAfeeArtemis!88718D8C584D
VBA32BScope.Trojan.Download
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DL723
RisingDownloader.Sinresby!8.2BE9 (C64:YzY0Othv6VGwzWQ3)
IkarusTrojan.Win32
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
BitDefenderThetaGen:NN.ZexaF.36608.@pKfaCGCn2ab
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b60fb4
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Sinresby!pz?

TrojanDownloader:Win32/Sinresby!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment