Win32.downloader.gen is a Trojan downloader that propagates to targeted PCs with the help of social engineering. Win32.downloader.gen will strive to control and induce a victim to carry out an action or to reveal private details inadvertently or against his/her will. Win32.downloader.gen can also circulate via spam email messages carrying malevolent attachments. Win32.downloader.gen can distribute other malware infections to the corrupted PC. While being installed, Win32.downloader.gen makes system changes by dropping and executing harmful files. Win32.downloader.gen can grab confidential information, incorporating running Windows version on the compromised PC.

Technical Information

File System Details

Win32.downloader.gen creates the following file(s):
# File Name
1 C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
2 C:\Windows\system32\lsm.exe
3 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
4 C:\Windows\system32\SLsvc.exe
5 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
6 C:\Program Files\Motorola\MotForwardDaemon\ForwardDaemon.exe
7 C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
8 C:\Program Files\Creative\Volume Panel\VolPanlu.exe
9 C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
10 C:\Windows\system32\dmwu.exe
11 C:\Windows\system32\WebUpdateSvc4.exe
12 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
13 C:\Windows\system32\Dwm.exe
14 C:\Program Files\Windows Media Player\wmpnscfg.exe
16 C:\Program Files\iPod\bin\iPodService.exe
17 C:\Program Files\Microsoft Security Client\msseces.exe
18 C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
19 C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
20 C:\Program Files\Google\Chrome\Application\chrome.exe
21 C:\Windows\system32\SearchFilterHost.exe
22 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
23 C:\Windows\system32\vssvc.exe
24 c:\Program Files\Microsoft Security Client\MsMpEng.exe
25 C:\Windows\system32\wininit.exe
26 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
27 C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
28 C:\Windows\System32\spoolsv.exe
29 C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
30 C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
31 C:\Windows\system32\taskeng.exe
32 C:\Program Files\Verizon\McciTrayApp.exe
33 C:\Windows\System32\Ctxfihlp.exe
34 C:\Windows\system32\lxbccoms.exe
35 C:\Windows\system32\SearchIndexer.exe
36 c:\Program Files\Microsoft Security Client\NisSrv.exe
37 C:\Windows\System32\jmdp\stij.exe
38 C:\Program Files\Garmin\Express Tray\ExpressTray.exe
39 C:\Windows\ehome\ehsched.exe
40 C:\Windows\ehome\ehRecvr.exe
41 C:\Program Files\iTunes\iTunesHelper.exe
42 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
43 C:\Program Files\Skype\Phone\Skype.exe
44 C:\Windows\system32\SearchProtocolHost.exe
45 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
46 C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
47 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
48 C:\Program Files\Creative\Shared Files\CTAudSvc.exe
49 C:\Windows\system32\nvvsvc.exe
50 C:\Program Files\Bonjour\mDNSResponder.exe
51 C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
52 C:\Program Files\Common Files\Motive\McciCMService.exe
53 C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
54 C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
55 C:\Windows\WindowsMobile\wmdcBase.exe
56 C:\Program Files\Google\Update\\GoogleCrashHandler.exe
57 C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
58 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
59 C:\Windows\System32\WUDFHost.exe
60 C:\Windows\Explorer.EXE
61 C:\Program Files\Windows Media Player\wmpnetwk.exe
62 C:\Windows\ehome\ehmsas.exe
63 C:\Windows\System32\mobsync.exe
64 C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
65 C:\Windows\ehome\ehtray.exe
66 C:\Program Files\Google\Drive\googledrivesync.exe
67 C:\Users\GregAdmin\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
68 C:\Windows\system32\wbem\wmiprvse.exe
69 C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
70 C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
71 C:\Windows\system32\svchost.exe -k GPSvcGroup
72 C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
73 C:\Windows\System32\svchost.exe -k WerSvcGroup
74 C:\Windows\System32\svchost.exe -k swprv
75 C:\Windows\system32\svchost.exe -k rpcss
76 C:\Windows\system32\svchost.exe -k netsvcs
77 C:\Windows\system32\svchost.exe -k NetworkService
78 C:\Windows\system32\svchost.exe -k imgsvc
79 C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
80 C:\Windows\system32\svchost.exe -k DcomLaunch
81 C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
82 C:\Windows\system32\svchost.exe -k LocalService
83 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
84 C:\Windows\system32\svchost.exe -k WindowsMobile

