Home Malware Programs Trojans Downloader

Downloader

Posted: November 4, 2009

Threat Metric

Ranking: 14,513
Threat Level: 7/10
Infected PCs: 6,490
First Seen: July 24, 2009
Last Seen: July 29, 2023
OS(es) Affected: Windows

Downloader is a malicious backdoor trojan that runs in the background and allows hackers remote access to an infected computer or network. Downloader uses a program that downloads files from the Internet to a local computer. Downloader can also log keystrokes and send this information to remote servers for hackers to gain access. Downloader contains characteristics of a severe security risk and should be removed from the system immediately.

Aliases

PSW.Banker5.BWES [AVG]W32/Murlo.LHI!tr.dldr [Fortinet]Win-Trojan/Bumat.428544 [AhnLab-V3]Trojan:Win32/Banker.O [Microsoft]TR/Delf.pvh [AntiVir]TrojWare.Win32.Trojan.Agent.~MIC [Comodo]Trojan.Generic.5651158 [BitDefender]Backdoor.Win32.Delf.xvw [Kaspersky]Trojan.Delf-11405 [ClamAV]W32/Trojan4.VOM [F-Prot]Generic.dx!yds [McAfee]BackDoor.Generic13.ADOV [AVG]W32/Delf.XYA!tr.bdr [Fortinet]Backdoor.Win32.Delf [Ikarus]Trojan/Win32.Gen [AhnLab-V3]
More aliases (2013)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\GetBooks\GetBooks.exe File name: GetBooks.exe
Size: 491 KB (491008 bytes)
MD5: c414ccc1fd0b6dbcfe661159b4614e33
Detection count: 581
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\GetBooks
Group: Malware file
Last Updated: April 8, 2013
%ALLUSERSPROFILE%\AppData\Local\Temp\Macromedia\swfupdate\swfupdate.dll File name: swfupdate.dll
Size: 75.26 KB (75264 bytes)
MD5: 59546ca0bc6cf1cad3417c2d2da6c48e
Detection count: 176
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\AppData\Local\Temp\Macromedia\swfupdate
Group: Malware file
Last Updated: July 18, 2011
C:\TCSL\Utilities\Dr.WebH5\DrWU\DrWU.exe File name: DrWU.exe
Size: 53.24 KB (53248 bytes)
MD5: 3d87bdfa4a528e8af10d166d135310ba
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: C:\TCSL\Utilities\Dr.WebH5\DrWU\DrWU.exe
Group: Malware file
Last Updated: July 29, 2023
%WINDIR%\system32\config\systemprofile\BERTOLI\Impostazioni locali\Dati applicazioni\wins.exe File name: wins.exe
Size: 1.58 MB (1586176 bytes)
MD5: be1991936c692cbee0a9d9395952f88f
Detection count: 122
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\BERTOLI\Impostazioni locali\Dati applicazioni
Group: Malware file
Last Updated: July 1, 2011
C:\Users\<username>\AppData\Local\Temp\icvcc.exe File name: icvcc.exe
Size: 41.58 KB (41581 bytes)
MD5: 35dbb1e50e99067797546e5103778a3b
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\icvcc.exe
Group: Malware file
Last Updated: April 20, 2022
%TEMP%\imhwsvynza File name: imhwsvynza
Size: 62.46 KB (62464 bytes)
MD5: 2b37499473872485a990dc86802fd6ab
Detection count: 85
Path: %TEMP%
Group: Malware file
Last Updated: September 26, 2011
%SystemDrive%\Users\<username>\AppData\Local\install_flash_player.exe File name: install_flash_player.exe
Size: 747.52 KB (747520 bytes)
MD5: 93fbab791bff6262c8bef0ecc5b205bb
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Local
Group: Malware file
Last Updated: January 21, 2013
%WINDIR%\wscript32.exe File name: wscript32.exe
Size: 151.55 KB (151552 bytes)
MD5: 50d456f8ceb9ab8d93e2f5d2f57b50ff
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: July 27, 2011
%APPDATA%\WinDir\Bios.exe File name: Bios.exe
Size: 1.53 KB (1536 bytes)
MD5: 3ea68e8aca7bbd86b11ed216504556cd
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\WinDir
Group: Malware file
Last Updated: October 3, 2011
%TEMP%\1cpawzqr1cz47.exe File name: 1cpawzqr1cz47.exe
Size: 484.35 KB (484352 bytes)
MD5: 363081e0666b590f271bc72f2c64d5d4
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: March 1, 2013
%USERPROFILE%\Start Menu\Programs\Startup\dxdiag.exe File name: dxdiag.exe
Size: 52.22 KB (52224 bytes)
MD5: 6fc45d4322d8f6e38459624dc9d83480
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: August 10, 2011
%ALLUSERSPROFILE%\Dados de aplicativos\SysUtlis.exe File name: SysUtlis.exe
Size: 1.64 MB (1649152 bytes)
MD5: 0cc652e775905be1a0f1511ab18498e4
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Dados de aplicativos
Group: Malware file
Last Updated: April 8, 2013
C:\WINDOWS\SysWOW64\nvtsecurity.exe File name: nvtsecurity.exe
Size: 683.52 KB (683520 bytes)
MD5: 5c53517d091f97b869338bf211eaf75f
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\WINDOWS\SysWOW64\nvtsecurity.exe
Group: Malware file
Last Updated: October 25, 2022
%WINDIR%\system32\mtcpxl32.dLL File name: mtcpxl32.dLL
Size: 14.84 KB (14848 bytes)
MD5: 7ac01038715e34a8742421a231fc6db7
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dLL
Path: %WINDIR%\system32
Group: Malware file
Last Updated: June 13, 2019
%PROGRAMFILES%\WithMoa\withmoa.exe File name: withmoa.exe
Size: 368.64 KB (368640 bytes)
MD5: c362febaa1a2867d4d95b2cb6aa447c4
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\WithMoa
Group: Malware file
Last Updated: July 11, 2011
%USERPROFILE%\Local Settings\Application Data\NVIDIA Corporation\Update\daemonupd.exe File name: daemonupd.exe
Size: 68.6 KB (68608 bytes)
MD5: 736db4acb9d51f08494ca9eaa06635f9
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\NVIDIA Corporation\Update
Group: Malware file
Last Updated: October 14, 2011
%WINDIR%\system32\MsgrUpd.exe File name: MsgrUpd.exe
Size: 403.45 KB (403456 bytes)
MD5: e99b8048e9e592aa640d5db89c01ff32
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: August 30, 2011
%PROGRAMFILES%\Favorite_Icons\FavoriteIconsUpdate.exe File name: FavoriteIconsUpdate.exe
Size: 199.83 KB (199832 bytes)
MD5: b78cfa6fa96130e257303507ba4f72be
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Favorite_Icons
Group: Malware file
Last Updated: January 28, 2013
%USERPROFILE%\adg.exe File name: adg.exe
Size: 34.3 KB (34304 bytes)
MD5: 4e2e12fc2e328562043d36ed4c513e9f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: September 29, 2011
%APPDATA%\C.exe File name: C.exe
Size: 190.46 KB (190464 bytes)
MD5: 3e4eb02fbddc94cb87ecc9f11c13bc61
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 15, 2020
%LOCALAPPDATA%\DownloadSS\Unanamed.exe File name: Unanamed.exe
Size: 1.57 MB (1570816 bytes)
MD5: e3821a71194595f9082662b6bc3794e3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\DownloadSS
Group: Malware file
Last Updated: April 8, 2013

More files

Related Posts

Loading...