Threat Database Trojans Trojan.Downloader.CN

Trojan.Downloader.CN

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,368
Threat Level: 80 % (High)
Infected Computers: 166
First Seen: November 6, 2021
Last Seen: July 15, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.CN on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Downloader.CN?

Trojan.Downloader.CN is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. The ".CN" suffix may indicate a specific variant or classification of the malware, but it is not a definitive indicator of its origin or purpose.

How Trojan.Downloader.CN Operates

Trojan.Downloader.CN typically operates by exploiting vulnerabilities in your system or tricking you into downloading and installing it. Once installed, it can connect to a remote server to download and install additional malware, which can include viruses, spyware, adware, and other types of malicious software. This can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information. Trojan.Downloader.CN may also attempt to disable your antivirus software or other security measures to prevent detection and removal.

Symptoms of Infection

The symptoms of a Trojan.Downloader.CN infection can vary, but common indicators include slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on your desktop. You may also notice that your antivirus software is disabled or that your system is crashing frequently. In some cases, you may not notice any symptoms at all, which is why it is essential to run regular virus scans and maintain up-to-date antivirus software.

How to Remove Trojan.Downloader.CN

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable antivirus tool, such as SpyHunter, and run a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan with your antivirus software to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.CN from your system requires prompt action and a thorough approach. By following the steps outlined above, you can help to ensure that your system is clean and secure. It is also essential to maintain good security practices, including running regular virus scans, keeping your operating system and software up to date, and being cautious when downloading and installing programs or files from the internet. By taking these steps, you can help to protect your system and your personal information from the risks associated with Trojan.Downloader.CN and other types of malware.

Analysis Report

General information

Family Name: Trojan.Downloader.CN
Signature status: Self Signed

Known Samples

MD5: c0b3b44c311c540947d60f58d5063b2f
SHA1: cbc4bce38d6a9afca420ea0d093b394c3ceb6271
SHA256: BFFCB094E24C891EC242A90D49017514F14E64D4895805A58233E0B98E362AA1
File Size: 7.75 MB, 7749368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description Zapya Install Program
File Version 1.0.0.0
Legal Copyright Copyright©2011-2014 DewMobile,Inc.
Legal Trademarks Zapya,kuaiya,快牙
Product Name Zapya-en
Product Version 1.7.0.0

Digital Signatures

Signer Root Status
DewMobile USA , Inc. COMODO RSA Code Signing CA Self Signed

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 439
Potentially Malicious Blocks: 17
Whitelisted Blocks: 422
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 x x x x x x x 0 x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\richedit1 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_common_checkbox_default.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_common_checkbox_selected.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_common_input_frame.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_common_input_modify_default.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_common_input_modify_pressed.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bg.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bg2.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bg3.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bt_imsetup_default.png Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\zapya_install_bt_imsetup_focused.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bt_normal.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bt_pressed.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bt_return_default.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_bt_return_focused.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_close.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_close_pressed.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_confirm_default.png.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_confirm_pressed.png.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_launch_normal_completed.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_launch_pressed_completed.png Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zapya_install_progress.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{5beb75bb-d08f-4258-b2c8-7f7ed3cbf5ce}\is\1361.xs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{5beb75bb-d08f-4258-b2c8-7f7ed3cbf5ce}\is\1506.xs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{5beb75bb-d08f-4258-b2c8-7f7ed3cbf5ce}\isshell.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{5beb75bb-d08f-4258-b2c8-7f7ed3cbf5ce}\res\1525.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{5beb75bb-d08f-4258-b2c8-7f7ed3cbf5ce}\res\7805.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\{98d9c9dc-2e58-4d24-942a-e4ad7a3135b4}.dat Generic Read,Write Data,Write Attributes,Write extended,Append data

Related Posts

Trending

Most Viewed

Loading...