Threat Database Trojans Trojan.Downloader.Gen.FG

Trojan.Downloader.Gen.FG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,433
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: December 20, 2025
Last Seen: June 28, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Gen.FG on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and compromised security. In this report, we will provide an overview of Trojan.Downloader.Gen.FG, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Downloader.Gen.FG?

Trojan.Downloader.Gen.FG is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to evade detection by security software. The "Downloader" part of the name indicates that this malware is capable of downloading and installing additional malicious software on your computer. The "Gen.FG" part of the name is a generic detection name that indicates that this malware is a variant of a known Trojan horse family.

How Trojan.Downloader.Gen.FG Operates

Trojan.Downloader.Gen.FG operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can download and install additional malicious software, including viruses, spyware, and ransomware. This malware can also communicate with its creators, allowing them to remotely control your computer and steal sensitive information, such as login credentials and financial data. Trojan.Downloader.Gen.FG can also modify system settings and files, leading to system crashes, freezes, and errors.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Gen.FG infection can vary, but common signs include slow system performance, pop-up ads, and unexpected changes to system settings. You may also notice that your browser is being redirected to suspicious websites, or that your computer is crashing or freezing frequently. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware.

How to Remove Trojan.Downloader.Gen.FG

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove Trojan.Downloader.Gen.FG and any other malware that may be present on your system.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.Gen.FG from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure that your system is secure and free from malware. Remember to always be cautious when downloading software or files from the internet, and to regularly scan your system for malware to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the help of a professional malware removal service.

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.FG
Signature status: Hash Mismatch

Known Samples

MD5: bd009e3a5278d01562c42a09b054ddf9
SHA1: 2d4374ed9e0593627846ee5f88265a92a9e02bed
SHA256: 49F5D94265CF3C03CEE9B0CD41928024DD85291B21BAB2DC1BA5FD4F9209070C
File Size: 433.02 KB, 433024 bytes
MD5: d2e329548752cd994b771fc19dba0204
SHA1: 4c27d8aeaab365dc63d624ebb63ea2fb9c678460
SHA256: 2AF41EA9AD046FC03FDA5324CC719BDA9CC3A05BB179CFDAFB6B94E038321C34
File Size: 485.76 KB, 485760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have relocations information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Cloanto Corporation
File Description MenuBox
File Version 5, 2, 2, 0
Internal Name MenuBox
Legal Copyright Copyright © 1998-2012 Cloanto Corporation
Legal Trademarks Cloanto® is a registered trademark of Cloanto Corporation
Original Filename MenuBox.exe
Product Name MenuBox
Product Version 5, 2, 2, 0

Digital Signatures

Signer Root Status
Cloanto Corporation VeriSign Class 3 Code Signing 2010 CA Hash Mismatch

File Traits

  • x86

Block Information

Total Blocks: 2,035
Potentially Malicious Blocks: 228
Whitelisted Blocks: 1,807
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x x 0 x 0 x x x x x x x x x 0 0 0 x 0 0 0 x 0 0 0 x 0 x 0 0 x x x 0 x x x x x x 0 x x x 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 0 x x x 1 x x x x x x x x x x x x x x x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 x x 0 x 0 x 0 x x x x 0 x x 0 0 x x x 0 x 0 x x x x x x x x x x 0 0 x x x x x x x x x x 0 0 x x x x x x 0 x 0 x x x x x 0 x x x 0 0 0 0 x x x x x x x x x x x x x 0 0 0 0 x x x 0 0 x x x x x 0 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x x 0 x x x 0 x x x x x x x 0 x x x x 0 x x x x x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 x x x x x x x 0 x x 0 x x 0 0 x 0 x 0 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 1 0 0 1 0 0 0 0 0 0 1 1 1 0 3 1 1 0 1 1 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 3 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 2 2 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...