Trojan

UDS:Trojan-Downloader.Win32.Satacom.ld removal instruction

Malware Removal

The UDS:Trojan-Downloader.Win32.Satacom.ld is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Downloader.Win32.Satacom.ld virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk

How to determine UDS:Trojan-Downloader.Win32.Satacom.ld?


File Info:

name: 286342993DD3A57B8712.mlw
path: /opt/CAPEv2/storage/binaries/c29101951c1f73ba5865e7d6fbbd40761f06adf75d46a8a4f3a17932c2dda8d9
crc32: D674C4F9
md5: 286342993dd3a57b8712b293ad4f2f0e
sha1: 36115bde3d4750d9d1d1a265bc94567059047f0b
sha256: c29101951c1f73ba5865e7d6fbbd40761f06adf75d46a8a4f3a17932c2dda8d9
sha512: 46e45daa267a9aa522f8ff1b44078823bba1eeebff71d24125058aad010a146da24fcb43aef604788564a6c9f541ee004a3f9559b139c4b1b19e73043d4be5f7
ssdeep: 49152:tBuZrEUnfpLL69OFUVI7p3055DdN7POGjN:7kLnRWOAgpk55ljN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BCA5D03FF268A53EC46A1B3245B38220997B7A61B81A8C1F47FC354CCF765601E3B656
sha3_384: e62bacb2e1922328733e732680eb71013a592cdc04b2317018feb960fa59afbdbfc64c22fc5b93ae02030d08b6d5dc40
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: instaaleer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: instaaleer
ProductVersion: 100.102.03
Translation: 0x0000 0x04b0

UDS:Trojan-Downloader.Win32.Satacom.ld also known as:

MicroWorld-eScanGen:Variant.Zusy.435211
FireEyeGen:Variant.Zusy.435211
CyrenW32/Kryptik.HGW.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GenKryptik.FYMJ
KasperskyUDS:Trojan-Downloader.Win32.Satacom.ld
BitDefenderGen:Variant.Zusy.435211
CynetMalicious (score: 100)
EmsisoftGen:Variant.Zusy.435211 (B)
VIPREGen:Variant.Zusy.435211
GDataGen:Variant.Zusy.435211
AviraHEUR/AGEN.1251348
ArcabitTrojan.Zusy.D6A40B
ZoneAlarmUDS:Trojan-Downloader.Win32.Satacom.ld
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R510475
ALYacGen:Variant.Zusy.435211
MAXmalware (ai score=81)
MalwarebytesMalware.AI.3992485547
AvastFileRepMalware [Cryp]
RisingTrojan.Generic@AI.92 (RDML:Zc/CQw4g6hnmM8SzEuY6Ag)
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Cryp]

How to remove UDS:Trojan-Downloader.Win32.Satacom.ld?

UDS:Trojan-Downloader.Win32.Satacom.ld removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment