Malware

Should I remove “Win32:Downloader-RPC [Trj]”?

Malware Removal

The Win32:Downloader-RPC [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-RPC [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Win32:Downloader-RPC [Trj]?


File Info:

name: D28826D05854EC1475A7.mlw
path: /opt/CAPEv2/storage/binaries/01807166ebb92daae7260d491a1b67fbd91ed6e6daab7ec070b4442edd6ed8a3
crc32: 997D2F66
md5: d28826d05854ec1475a7298dca397a82
sha1: 74cda43e85c678b278523097f78ce6c2da1f7c90
sha256: 01807166ebb92daae7260d491a1b67fbd91ed6e6daab7ec070b4442edd6ed8a3
sha512: 023cc4ce230275281504613bdc1817454c1f4d33533e5a128d4dba11bee95149d0617487591b5db7309e15596b45b1c7d46dc38fb15cec9b843078dc3135ae4c
ssdeep: 12288:87TlR4i519QQwzpKslllKgA/Y6BQKSJvgld7fN0U2KualwGO9GqfLpYu9scQUi3h:87xR4i5s1flvoYAQtvId+U1+Lb9Yuy6G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12BF4235277CF82AFC19CE8324EA20E57BF62D23BD9265E6729A1C1C1191C613B84CC1E
sha3_384: 3da34114b0af707778a6cd781b64945468fbf623741550ccbd98b6527f2b0aa2135b24ee545750f1430db7151a32ebdc
ep_bytes: ff350230400058508d3dab2040008114
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32:Downloader-RPC [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.d28826d05854ec14
CAT-QuickHealTrojan.Lethic.B
McAfeeFakeAV-SecurityTool.nk
MalwarebytesTrojan.LameShield
VIPRETrojan.VIZ.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040797b1 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.05854e
ArcabitTrojan.VIZ.Gen.1
BaiduWin32.Trojan.Kryptik.hs
VirITTrojan.Win32.FakeAV_s.TE
CyrenW32/Zbot.GT.gen!Eldorado
SymantecSecShieldFraud!gen10
ESET-NOD32a variant of Win32/Kryptik.AQCF
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Fakealert.crkalq
SUPERAntiSpywareTrojan.Agent/Gen-FraudSecurity
MicroWorld-eScanTrojan.VIZ.Gen.1
RisingTrojan.Generic@AI.100 (RDML:Re5n5AnoTpdCC1iSNR1pJA)
Ad-AwareTrojan.VIZ.Gen.1
SophosML/PE-A + Troj/Zbot-DDW
ComodoTrojWare.Win32.Kryptik.AQBV@4t9vb6
DrWebBackDoor.Slym.1053
TrendMicroBKDR_KELIHOS.SM
McAfee-GW-EditionFakeAV-SecurityTool.nk
Trapminemalicious.high.ml.score
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Tepfer.Gen
AviraTR/Winwebsec.ooiuwo
MAXmalware (ai score=88)
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftBackdoor:Win32/Kelihos.F
ViRobotTrojan.Win32.A.PSW-Tepfer.770560.NZ
GDataTrojan.VIZ.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R47804
Acronissuspicious
VBA32Trojan.FakeAV.01657
ALYacTrojan.VIZ.Gen.1
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KELIHOS.SM
TencentWin32.Init.QQRob.dbsy
YandexTrojan.GenAsa!RAhuqEvOuTE
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ATCI!tr
BitDefenderThetaGen:NN.ZexaF.34606.VqW@aGR8I!jc
AVGWin32:Downloader-RPC [Trj]
AvastWin32:Downloader-RPC [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Downloader-RPC [Trj]?

Win32:Downloader-RPC [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment