Win32:Downloader-PKU [Trj]
Contents of this article is about Win32:Downloader-PKU [Trj]. This page includes description, technical aspects, and removal guide to delete the threat from your computer.
Win32:Downloader-PKU [Trj] is a detection for a variant of malware that is created to drop and execute files onto the infected computer. Members of the Win32:Downloader clan is harmful software programs that share the main payload of downloading unwanted contents. There are variations for the program it may download based on the type of variant infecting the computer.
Damage Level: Medium
Systems Affected: Windows 9x, 2000, XP, Windows Vista/7
Characteristics
When Win32:Downloader-PKU [Trj] is executed on the computer, it will attempt to connect to specified server and download another component. Location or address of the server are mostly injected into the Trojan code, this only implies that it fetches malware from a fixed place. However, some may encounter a variant of Win32:Downloader-PKU [Trj] that has tasks of downloading modules base on the commands received from a remote attacker.
There are various reasons why attackers are releasing Win32:Downloader-PKU [Trj] prior to the main infection. This initial threat is literally small in size and stealth programs that can evade antivirus detection. There is almost zero sign of the Trojan’s presence even if it is already inside the computer and attacking the core files. Probably signs of Win32:Downloader-PKU [Trj] are not visually obvious, however, its significant effect on network performance is evident. While fetching file from a remote server, Internet traffic is badly affected especially if it is large in size.
Distribution
Nearly all Trojan downloader including Win32:Downloader-PKU [Trj] is acquired by victims from compromised web sites. Some observation points that file-sharing network is the second mostly used method to deploy the threat. Once Win32:Downloader-PKU [Trj] arrives on a protected computer; updated security program can immediately catch and name the threat. See the image below.
![Win32:Downloader-PKU Win32:Downloader-PKU [Trj]](http://www.precisesecurity.com/wp-content/uploads/2012/08/Win32-Downloader-PKU.png)
How to Remove Win32:Downloader-PKU [Trj]
1. Temporarily Disable System Restore if you are using Windows XP. For Windows Vista/7 users, you may use System Restore to return Windows to a previous clean state. However, you must have a saved restore points to accomplish this. Otherwise, proceed with the removal process.
2. Open your antivirus application and update the virus definitions. This method ensures that your antivirus program can detect even newer variants of Win32:Downloader-PKU [Trj].
3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Select Safe Mode with Networking.
- System will boot Windows loading only necessary drivers and system files.
4. Open your antivirus program and run a full system scan. After the scan, delete all infected items. If unable, better place them in quarantine. Once the scan is complete, please proceed with the next step.
Online Virus Scanner:
Another way to remove Win32:Downloader-PKU [Trj] without the need to install additional antivirus application is to perform a thorough scan with free online virus scanner that can be found on websites of legitimate anti-virus and security provider.
5. Go to Online Virus Scanner list and run a virus scan. This may require plug-ins, add-on or Activex object, please install if you want to proceed with scan.
6. After completing the necessary download, your system is now ready for online virus scanning.
7. Select an option in which you can thoroughly scan the computer to make sure that it will find and delete entirely all infections not detected on previous scan.
8. Remove or delete all detected items.
9. When scanning is finished, you may now restart the computer in normal mode.
Automatic Removal of Win32:Downloader-PKU [Trj]
In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.Alternative Removal Method for Win32:Downloader-PKU [Trj]
Option 1 : Use Windows System Restore to return Windows to previous state
If Win32:Downloader-PKU [Trj] enters the computer, there is a big chance that Windows files, registry entries and other essential components are also infected. System Restore can reinstate clean system files by restoring the configuration to an earlier date. The method also replaces compromised files with a clean version. If you have a saved restore point before Win32:Downloader-PKU [Trj] infiltrates the PC, we highly encourage you to execute this procedure if none of the above works. You may proceed with Windows System Restore, click here to see the full procedure.