Threat Database Trojans Trojan.Downloader.Gen.PK

Trojan.Downloader.Gen.PK

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,857
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: March 13, 2026
Last Seen: April 21, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Gen.PK on your system indicates a potential security threat. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and compromised security. In this report, we will provide an overview of what Trojan.Downloader.Gen.PK is, how it operates, and the steps you can take to remove it from your system.

What Is Trojan.Downloader.Gen.PK?

Trojan.Downloader.Gen.PK is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. The "Downloader" part of the name indicates that this malware is capable of downloading and installing additional malware or other types of software. The "Gen.PK" part of the name is a generic detection name that indicates that this malware is a variant of a known Trojan horse family.

How Trojan.Downloader.Gen.PK Operates

Trojan.Downloader.Gen.PK operates by exploiting vulnerabilities in your system or by tricking you into installing it. Once installed, it can download and install additional malicious software, including other Trojans, spyware, adware, and ransomware. This malware can also steal your personal data, including login credentials, credit card numbers, and other sensitive information. Additionally, it can compromise your system's security, allowing hackers to gain remote access to your computer.

Symptoms of Infection

If your system is infected with Trojan.Downloader.Gen.PK, you may notice a range of symptoms, including slow system performance, frequent crashes, and unexpected pop-ups or advertisements. You may also notice that your system is behaving erratically, or that your personal data is being stolen. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans and maintain up-to-date security software.

  • Slow system performance
  • Frequent crashes
  • Unexpected pop-ups or advertisements
  • Erratic system behavior
  • Theft of personal data

How to Remove Trojan.Downloader.Gen.PK

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading.
  2. Run a full scan of your system using a reputable anti-malware tool, such as SpyHunter.
  3. Uninstall any suspicious programs or software that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings.
  5. Reboot your system and run another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.Gen.PK from your system requires careful attention to detail and a comprehensive approach to security. By following the steps outlined in this report, you can help to ensure that your system is free from this malware and any other related threats. Remember to always maintain up-to-date security software, run regular virus scans, and be cautious when installing new software or opening email attachments from unknown sources. By taking these precautions, you can help to protect your system and your personal data from the risks associated with Trojan.Downloader.Gen.PK and other types of malware.

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.PK
Signature status: No Signature

Known Samples

MD5: 53bd1d2ea8e94213dc54c48ffdab2963
SHA1: 999817a3e29d63b98bf3960ffaa44d5161310531
SHA256: 692B800B4F6F03046AB694FCFC8356ADA003513622DE605D6D61165E4D7F5820
File Size: 1.55 MB, 1547776 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Robert Simpson, et al.
File Description System.Data.SQLite Interop Assembly
File Version 1.0.109.0
Internal Name SQLite.Interop
Legal Copyright Public Domain
Original Filename SQLite.Interop.dll
Product Name System.Data.SQLite
Product Version 1.0.109.0
S Q Lite Company Name D. Richard Hipp, et al.
S Q Lite Copyright https://www.sqlite.org/copyright.html
S Q Lite Description SQLite Database Engine
S Q Lite Source Id 2018-06-04 19:24:41 c7ee0833225bfd8c5ec2f9bf62b97c4e04d03bd9566366d5221ac8fb199a87ca
S Q Lite Version 3.24.0
Source Id 86636b58e29f85d17a2194bfacdb3b989a81b2bb 2018-08-11 19:58:48 UTC

File Traits

  • dll
  • x64

Block Information

Total Blocks: 6,267
Potentially Malicious Blocks: 508
Whitelisted Blocks: 5,759
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 2 0 0 0 0 0 0 x x 0 x x x x x x x 0 x x x x x 0 x 0 x x 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x x x 0 0 x x x 0 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x x 0 1 0 0 0 0 0 1 0 0 0 1 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 1 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 1 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 1 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 x 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 1 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x x x 0 x x 0 0 x 0 0 0 0 0 0 x 0 x 0 x x x 0 x 0 x x x x x 0 x 0 0 0 0 0 x x 0 0 0 0 1 0 x 0 x x x 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x 0 x x 0 x 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x 0 x x x 0 0 x x 0 0 x 0 0 x x x 0 x x x x x 0 x x x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x x 0 0 0 0 x x x 0 x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 x 0 x x x 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x x 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...