Threat Database Trojans Trojan.Downloader.Gen.SE

Trojan.Downloader.Gen.SE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,521
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: May 5, 2026
Last Seen: June 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Gen.SE on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and compromised security. In this report, we will provide an overview of the Trojan.Downloader.Gen.SE threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Downloader.Gen.SE?

Trojan.Downloader.Gen.SE is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The ".Gen" suffix indicates that this is a generic detection, meaning that it is a broad category of malware rather than a specific variant. Trojan horses are a type of malware that disguises itself as a legitimate program, but actually allows unauthorized access to your system. They can be used to steal sensitive information, install additional malware, or take control of your system.

How Trojan.Downloader.Gen.SE Operates

Trojan.Downloader.Gen.SE operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can download and install additional malware, including viruses, spyware, and adware. This can lead to a range of problems, including system crashes, slow performance, and compromised security. The malware can also be used to steal sensitive information, such as login credentials, credit card numbers, and personal data.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Gen.SE infection can vary, but common signs include slow system performance, frequent crashes, and unfamiliar programs or icons on your desktop. You may also notice unusual network activity, such as unexpected connections to unknown servers or unusual data transfers. Additionally, you may receive alerts from your security software or notices of suspicious activity from your bank or other online services.

How to Remove Trojan.Downloader.Gen.SE

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your knowledge or consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.Gen.SE from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure that your system is secure and that your personal data is protected. Remember to always be cautious when downloading and installing software, and to keep your security software up to date to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the advice of a qualified security professional.

Analysis Report

General information

Family Name: Trojan.Downloader.Gen.SE
Signature status: No Signature

Known Samples

MD5: 8f1cc027624a0da4416b6dea1787c130
SHA1: 11fd5aabcd55dadd3ed4e861aec4a20f24e85897
SHA256: B3D7F2C478A887580FD1D3D848C5E62B7B91D8173694CF6AA38EB923AC6C8977
File Size: 1.98 MB, 1982976 bytes
MD5: ea27fb04dfd60c5fbedd2bdc5ba46efa
SHA1: 02591b1ad4d27025234b157b296825309ee664b7
SHA256: 26210595727AE30048D0386A45E5B36CD7FD303E0A19862A108668EC652EAF10
File Size: 1.98 MB, 1982976 bytes
MD5: 049fa0fca57673e80a285196b4a2e194
SHA1: 9de928db3977a06c3ec2d01ec0f4fedbb761628d
SHA256: 4265F4ED3631F4176AA9EFAD07F3D381C54D890588E45B780FB162C6F22F9A80
File Size: 3.53 MB, 3534597 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Oleg N. Scherbakov
  • PFU Limited
File Description
  • 7z Setup SFX (x86)
  • SsUCommon DLL
File Version
  • 1.4.0.1795
  • 1, 2, 39, 0
Internal Name
  • 7ZSfxMod
  • SsUCommon.dll
Legal Copyright
  • (c) PFU Limited 2014-2024
  • Copyright © 2005-2010 Oleg N. Scherbakov
Original Filename
  • 7ZSfxMod_x86.exe
  • SsUCommon.dll
Private Build June 27, 2010
Product Name
  • 7-Zip SFX
  • SsUCommon.dll
Product Version
  • 1.4.0.1795
  • 1, 2, 39, 0

File Traits

  • dll
  • imgui
  • x86

Block Information

Similar Families

  • Agent.FRFA
  • Agent.ODC
  • Emotet.GX
  • ShellcodeRunner.FN
  • ShellcodeRunner.RHA
Show More
  • Trojan.Downloader.Gen.SE

Files Modified

File Attributes
c:\programdata\base_com\decalpha64.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\base_com\msvcp_win.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\base_com\physicsdesc13.yaml Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\base_com\shader.cfg Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\base_com\ssucommon.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\base_com\ucrtbase.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\43f98e2.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\decalpha64.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\decalpha64.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\msvcp_win.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\msvcp_win.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\physicsdesc13.yaml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\physicsdesc13.yaml Synchronize,Write Attributes
c:\users\user\appdata\local\temp\shader.cfg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\shader.cfg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ssucommon.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ssucommon.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ucrtbase.dll Synchronize,Write Attributes
c:\users\user\appdata\roaming\base_com\crisp.exe Read Attributes,Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴎ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃(獖}偫~엦1਷ˣ邯̃뫯ʃeꙥž¶i ꙥžr ֢vꙥž RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\11fd5aabcd55dadd3ed4e861aec4a20f24e85897_0001982976.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\02591b1ad4d27025234b157b296825309ee664b7_0001982976.,LiQMAxHB
(NULL) C:\Users\Rtsgpfgh\AppData\Local\Temp\DecAlpha64.exe

Trending

Most Viewed

Loading...