Trojan

Win32/TrojanDownloader.PurityScan (file analysis)

Malware Removal

The Win32/TrojanDownloader.PurityScan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.PurityScan virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanDownloader.PurityScan?


File Info:

name: F77B9768668E9B9F35AE.mlw
path: /opt/CAPEv2/storage/binaries/027d68ce064a8e0317f98a3da1a749c7a6bffa243c695ae9a0be88a0c0b1689f
crc32: 7AAC8C40
md5: f77b9768668e9b9f35aeac0e3e6e664f
sha1: 8586ce777482af5022cada8d2f81df9f5faa3457
sha256: 027d68ce064a8e0317f98a3da1a749c7a6bffa243c695ae9a0be88a0c0b1689f
sha512: cf624504513e466c92026a2a8828570f6a62313499a4de8d98aadb98d916b21a5f4ba4aa26c850e653a53c4506181b39929182789f2c2d4e779eae813ab96355
ssdeep: 3072:oNzztfivMVMYuFkV3qBnFqOLp4mvy2ACh3+j5z8UcTr/C:oVz8YurEmvy2AChozwPC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5249E1676F0C4B2DAE500315A646F3AEBBCFC340B25DA53CB984F462EA4DD1D2262D7
sha3_384: 6249b13e88954b14559ca692e893c7b10d0baea41aebd024244f2b0872824e114b9f95730ff4881c4c1e531916aa276b
ep_bytes: 558bec6aff6838c24100683ce9400064
timestamp: 2008-01-18 19:46:03

Version Info:

0: [No Data]

Win32/TrojanDownloader.PurityScan also known as:

MicroWorld-eScanTrojan.GenericKD.66470731
ClamAVWin.Downloader.39962-1
FireEyeGeneric.mg.f77b9768668e9b9f
ALYacTrojan.GenericKD.66470731
MalwarebytesMediaTickets.Adware.Advertising.DDS
ZillyaDownloader.PurityScan.Win32.259
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 005a1c161 )
K7GWTrojan-Downloader ( 0056a18b1 )
Cybereasonmalicious.8668e9
ArcabitTrojan.Generic.D3F6434B
BitDefenderThetaGen:NN.ZexaF.36196.nmZ@ae9TnBe
VirITAdware.Win32.MediaTicket.J
CyrenW32/PurityScan.A.gen!Eldorado
SymantecAdware.Purityscan
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.PurityScan
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.PurityScan.fn
BitDefenderTrojan.GenericKD.66470731
NANO-AntivirusTrojan.Win32.PurityScan.wnja
SUPERAntiSpywareAdware.ClickSpring-Variant
AvastWin32:PurityScan-BD [Trj]
TencentTrojan-DL.Win32.Purityscan.ka
EmsisoftTrojan.GenericKD.66470731 (B)
F-SecureTrojan.TR/Dldr.PurityScan.qqxhz
DrWebAdware.MediaTicket
VIPRETrojan.GenericKD.66470731
McAfee-GW-EditionBehavesLike.Win32.AdwareClickSpring.dt
Trapminemalicious.moderate.ml.score
SophosClickSpring (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.PurityScan.eq
AviraTR/Dldr.PurityScan.qqxhz
Antiy-AVLTrojan[Downloader]/Win32.PurityScan
XcitiumTrojWare.Win32.TrojanDownloader.Purityscan.~fn@20ug0g
MicrosoftTrojanDownloader:Win32/PurityScan.MI!MTB
ViRobotTrojan.Win32.A.Downloader.68677.C
ZoneAlarmTrojan-Downloader.Win32.PurityScan.fn
GDataTrojan.GenericKD.66470731
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R564985
Acronissuspicious
McAfeeAdware-ClickSpring.k
MAXmalware (ai score=85)
VBA32BScope.TrojanDownloader.PurityScan
Cylanceunsafe
PandaAdware/OuterInfo
RisingBackdoor.Win32.IRCbot.ged (CLASSIC)
YandexTrojan.DL.CLSpring.Gen
IkarusTrojan-Downloader.Win32.PurityScan
MaxSecureTrojan.Malware.1243576.susgen
FortinetW32/PurityScan.A!tr.dldr
AVGWin32:PurityScan-BD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/TrojanDownloader.PurityScan?

Win32/TrojanDownloader.PurityScan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment