Malware

Win32/DownloadAssistant.A potentially unwanted removal guide

Malware Removal

The Win32/DownloadAssistant.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DownloadAssistant.A potentially unwanted virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/DownloadAssistant.A potentially unwanted?


File Info:

crc32: C420965A
md5: bb9b75a2886c8e195089c3bc6409189f
name: BB9B75A2886C8E195089C3BC6409189F.mlw
sha1: 16a0cbf4afa152e2b6c66043cb373f0771ee26b6
sha256: dcd9e165044c48c9ec9ec772dcc771385fc86b07a6dfd77ece820fe04aca873d
sha512: 067718c0dbcca2ee951a4098dee1d5fa4652562dfc68ab2689cbb6d6c8bfe5e62bfd08382fec4356c82d4a3758e76855e2c06949945f010eb934a0952cbd9827
ssdeep: 12288:Je32v6EfnwWnkOhErfVSIpnDJPJgEYwAEROsKXu2oV10tiQUuJlQ0e70w5nlXih:JsWhooWVX2sebs1fuJrE0MlE3+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Install Assistant
InternalName: Setup_v3.206.exe
FileVersion: 3.0.0.105
CompanyName: Install Assistant
ProductName: HD Player
ProductVersion: 3.0.0.105
FileDescription: HD Player
OriginalFilename: Setup_v3.206.exe
Translation: 0x0409 0x04b0

Win32/DownloadAssistant.A potentially unwanted also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.DownloadAssistant.G
FireEyeGeneric.mg.bb9b75a2886c8e19
ALYacApplication.Bundler.DownloadAssistant.G
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 004c44db1 )
BitDefenderApplication.Bundler.DownloadAssistant.G
K7GWUnwanted-Program ( 004c44db1 )
Cybereasonmalicious.2886c8
CyrenW32/DownloadAssist.B.gen!Eldorado
SymantecDownloader
AvastFileRepMalware [PUP]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.DownloadAsist.gen
NANO-AntivirusTrojan.Win32.Vittalia.dwewuu
Ad-AwareApplication.Bundler.DownloadAssistant.G
EmsisoftApplication.Bundler.DownloadAssistant.G (B)
ComodoApplication.Win32.DownloadAssistant.S@5msx5i
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Vittalia.194
ZillyaTrojan.DownloadAssistGen.Win32.1
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosDownload Assistant (PUA)
JiangminDownloader.DownloadAsist.b
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare[AdWare]/Win32.DownloadAssistant.c
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitApplication.Bundler.DownloadAssistant.G
SUPERAntiSpywarePUP.DownloadAdmin/Variant
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DownloadAsist.gen
GDataApplication.Bundler.DownloadAssistant.G
AhnLab-V3PUP/Win32.Bundler.R149377
Acronissuspicious
McAfeeGenericRXCK-FK!BB9B75A2886C
MAXmalware (ai score=72)
VBA32BScope.Downloader.DownloadAsist
MalwarebytesPUP.Optional.DownLoadAdmin
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/DownloadAssistant.A potentially unwanted
RisingTrojan.Assistant!1.A3BC (CLASSIC)
YandexTrojan.GenAsa!2WJYNv6rGDw
SentinelOneStatic AI – Malicious PE – Downloader
FortinetRiskware/DownloadAsist
BitDefenderThetaAI:Packer.F5CC46C51F
AVGFileRepMalware [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Application.6f2

How to remove Win32/DownloadAssistant.A potentially unwanted?

Win32/DownloadAssistant.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment