<< Back to Top Threats
K7 Detection Name Affected OS Prevalence AV Definition Version
Trojan-Downloader ( 005d2a1b1 ) Windows Low 14.16.57571
MD5

5be444b3b278046ea16b5b4c430c37a3

SHA256

7f99bcecc41ac0eb9c6d765aa88ec35a164d80451be4c1cffc9771c92ab6a733

File Size

6,693,887 bytes

Packer Information

N/A

First Seen

04-11-2025

Last Seen

26-12-2025

Aliases

Win32/TrojanDownloader.Agent.IJU

Behavior Details

1. Dropped files:
5be444b3b278046ea16b.dat.tmp
Under the folder
C:\Users\\AppData\Local\Temp\is-T3587.tmp

2. Dropped files:
_setup64.tmp
Under the folder
C:\Users\\AppData\Local\Temp\is-FSE50.tmp\_isetup

3. Creates Registry:

Adds registry data
\x18\x00\x00\xc2N=\xf46{\xdc\x01

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

Adds registry data
hVd\xc7@\xf2\x95\x1e\x141{\x13x\x8a\xe8
\xee8\xcd\x1c\xc28O\xab4\xa8~\xc1\xd5I\xea7

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

Adds registry data
1

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence

Removal Instructions

1. Update the copy of K7 security to the latest version.
2. Scan the system completely and remove the detected files.
3. Open Windows registry editor.
4. Delete the registry data
\x18\x00\x00\xc2N=\xf46{\xdc\x01

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Owner

5. Delete the registry data
hVd\xc7@\xf2\x95\x1e\x141{\x13x\x8a\xe8
\xee8\xcd\x1c\xc28O\xab4\xa8~\xc1\xd5I\xea7

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\SessionHash

6. Delete the registry data
1

Under the key:
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000\Sequence
7. Close the Windows registry.
8. Restart the machine.