Threat Database Trojans Trojan.Downloader.Gen.AT

Trojan.Downloader.Gen.AT

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,463
Threat Level: 80 % (High)
Infected Computers: 18
First Seen: November 21, 2025
Last Seen: May 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Gen.AT indicates that your system has been compromised by a potentially malicious threat. This type of threat is generally associated with Trojans, which are malicious programs designed to allow unauthorized access to a computer system. The fact that it is classified as a downloader suggests that it may be used to download and install additional malware onto the infected system.

What Is Trojan.Downloader.Gen.AT?

Trojan.Downloader.Gen.AT is a type of malware that can compromise the security of your computer system. The "Gen" in its name suggests that it is a generic detection, indicating that it may not be a specific, well-known malware variant, but rather a broader category of threats that share similar characteristics. As a Trojan, it is designed to deceive users into installing it, often by disguising itself as a legitimate program or attachment.

How Trojan.Downloader.Gen.AT Operates

Once installed, Trojan.Downloader.Gen.AT can operate in various ways, depending on its intended purpose. It may be used to download and install additional malware, such as keyloggers, ransomware, or other types of Trojans. It can also be used to create backdoors, allowing unauthorized access to the infected system. In some cases, it may be used to steal sensitive information, such as login credentials, credit card numbers, or personal data.

Trojan.Downloader.Gen.AT can spread through various means, including infected software downloads, malicious email attachments, or exploited vulnerabilities in operating systems or applications. It can also be spread through infected websites or drive-by downloads, where a user's system is infected simply by visiting a compromised website.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Gen.AT infection can vary, but common indicators include slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on the desktop. You may also notice that your system is behaving erratically, such as crashing or freezing frequently. In some cases, you may receive warnings from your security software or notice that your antivirus program is disabled or not functioning properly.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar or suspicious programs
  • Increased network activity or unusual data transfers
  • Difficulty accessing or using certain system features or applications

How to Remove Trojan.Downloader.Gen.AT

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the threat
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform another full scan to ensure that the threat has been completely removed

Conclusion

Removing Trojan.Downloader.Gen.AT from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above and using reputable security software, you can help to protect your system and prevent future infections. It is essential to remain vigilant and to regularly scan your system for malware to ensure that you are safe from these types of threats. Remember to always use caution when downloading software or attachments, and to avoid suspicious links or websites to minimize the risk of infection.

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.AT
Signature status: Hash Mismatch

Known Samples

MD5: 33d9a545b0a944a95c2dc66b5c609cae
SHA1: 1b81f22616d1eb960b35fd5a3a2d4424cdb82979
SHA256: 25512075F8D85D5730E74C4046812321E3E1F242AB5AA6FED7D945224F7B3926
File Size: 224.26 KB, 224256 bytes
MD5: 4409c19165a13a56434eaa51c429713f
SHA1: 1a778f4dae1a6e5671d0dbdf4786110ab81dd3ce
SHA256: 14B8AEF16366278AC544609EF39EF7B9C8551B7FF6F11E8FADF2FA7F6F535D4A
File Size: 662.51 KB, 662512 bytes
MD5: 075c2e5ffb191a70496da05cd49bbeac
SHA1: 5bb1dd68f8df7a6060aef7aa61a88fd49012de62
SHA256: 9DE2D3D23EDB353F63CC8BC9B959007CEAA272B2E73AC69B8A24C989ABEDF71A
File Size: 797.46 KB, 797456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments 32 bit SQLite DLL compiled by www.netscantools.com
Company Name www.sqlite.org
File Description
  • sqlite3 Dynamic Link Library
  • WS_Log Dynamic Link Library
File Version
  • 4, 2, 5, 7
  • 3.31.1.0
Internal Name
  • sqlite3
  • WS_Log
Legal Copyright
  • Copyright (C) 2008
  • Copyright (C) 2020
Original Filename
  • sqlite3.dll
  • WS_Log.dll
Private Build for use with NetScanTools Products and Managed Switch Port Mapping Tool
Product Name
  • sqlite3 Dynamic Link Library
  • WS_Log Dynamic Link Library
Product Version
  • 4, 2, 5, 7
  • 3.31.1.0
Special Build Compiled by Northwest Performance Software, Inc. using Visual Studio 2012

Digital Signatures

Signer Root Status
Plex, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Northwest Performance Software, Inc. Sectigo RSA Code Signing CA Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,706
Potentially Malicious Blocks: 22
Whitelisted Blocks: 1,964
Unknown Blocks: 720

Visual Map

0 0 0 0 x x x ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 ? 0 ? ? 0 0 0 ? 0 0 0 1 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 x x x 0 ? ? ? 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 1 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? 0 0 ? ? 0 0 ? x 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? ? 0 1 1 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 ? ? 0 0 ? 0 ? ? ? 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 ? ? ? 0 0 0 ? ? ? 0 0 0 0 ? 0 0 0 ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 0 ? 0 ? 0 0 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 ? ? ? x ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 ? ? 0 ? ? 0 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 ? ? 0 0 0 ? 0 ? ? 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 ? ? ? 0 ? 0 0 ? 0 x ? 0 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 ? 0 ? ? 0 0 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? ? 0 ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? ? ? 0 0 ? 0 0 0 ? 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 0 ? ? 0 ? 0 0 0 ? 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 ? ? 0 ? ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 0 ? 0 0 ? 0 0 ? ? 0 0 0 ? ? ? ? 0 ? ? 0 ? 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1b81f22616d1eb960b35fd5a3a2d4424cdb82979_0000224256.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1a778f4dae1a6e5671d0dbdf4786110ab81dd3ce_0000662512.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5bb1dd68f8df7a6060aef7aa61a88fd49012de62_0000797456.,LiQMAxHB

Trending

Most Viewed

Loading...