Home Malware Programs Trojans Heur:trojan-Downloader.script.generic

Heur:trojan-Downloader.script.generic

Posted: August 17, 2011

Heur:Trojan-Downloader.script.generic is an alert for a generic script that's used to install unwanted and harmful software onto your PC. Because these scripts can be embedded on a variety of websites and in a variety of advertisements, the exact origin of any single Heur:Trojan-Downloader.script.generic can vary just as much as the potential Trojan or other malicious program that Heur:Trojan-Downloader.script.generic installs. In some cases, Heur:Trojan-Downloader.script.generic may also be a false positive, which can be fixed by bringing the relevant issue to the attention of the appropriate security company; such false positives are often fixed within the next update cycle. SpywareRemove.com malware experts recommend that you use secondary types of anti-malware programs to make sure whether an Heur:Trojan-Downloader.script.generic alert is a false positive or not before you risk exposing yourself to a possible Trojan. If your PC has become infected by Heur:Trojan-Downloader.script.generic, use appropriate security software to scan for and remove all Heur:Trojan-Downloader.script.generic-related infections and other system corruptions.

When You Can Shrug Off a Fake Heur:Trojan-Downloader.script.generic

Although SpywareRemove.com malware researchers haven't found any signs of deliberately faked Heur:Trojan-Downloader.script.generic warnings, a false positive Heur:Trojan-Downloader.script.generic is a common occurrence for certain types of security software. In some cases, a Heur:Trojan-Downloader.script.generic false alert can even block off reputable websites, such as prominent business company sites and email sites.

SpywareRemove.com malware analysts have observed that Heur:Trojan-Downloader.script.generic infections are somewhat more common for websites that use large amounts of scripts, as opposed to websites with minimal or no script usage. This includes Flash, JavaScript and ActiveX which are often employed by popular social networking and email websites. If you're maintaining a website and experience unusual Heur:Trojan-Downloader.script.generic errors, you can shorten your usage of scripts to avoid triggering these errors.

If you're certain that Heur:Trojan-Downloader.script.generic is a false positive, contact the company that sells the security software that's giving this alert. By providing information on what triggers this Heur:Trojan-Downloader.script.generic error, you can help to insure that the false positive is removed as soon as possible, potentially in the next threat definitions patch.

Why You Shouldn't Relax Against Heur:Trojan-Downloader.script.generic

Although many Heur:Trojan-Downloader.script.generic attacks are fake, SpywareRemove.com malware researchers have also discovered many Heur:Trojan-Downloader.script.generic attacks that are genuinely threatening and use actual dropper Trojans. Common side effects that are related to such attacks include:

Since Heur:Trojan-Downloader.script.generic has no hard-defined payload and can install many different types of threats, you should be prepared for anything and have appropriate anti-malware software ready to scan your PC for Heur:Trojan-Downloader.script.generic and any related infections.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\[RANDOM CHARACTERS] File name: %Temp%\[RANDOM CHARACTERS]
%System%\drivers\[RANDOM CHARACTERS] File name: %System%\drivers\[RANDOM CHARACTERS]

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run](Default) = "%System%\drivers\[RANDOM CHARACTERS]
Loading...