What it is
What you may notice
-
New processes or apps you didn’t install
-
Sudden pop-ups, redirects, or extensions appearing
-
CPU/disk spikes and security tools turning off or failing to update
How it gets in
-
Fake updates and bundled “free” installers
-
Phishing attachments or links (archives, scripts, macros)
-
Malvertising and drive-by downloads from sketchy sites
Remove it now (quick steps)
-
Disconnect from the internet to stop more payloads.
-
Run a full anti-malware scan; quarantine everything found and reboot.
-
Check startup items, scheduled tasks, services, and browser extensions; remove unknowns.
-
From a clean device, change passwords and enable MFA (in case a stealer was dropped).
-
Review firewall/DNS logs for domains contacted and block them.
Prevent it
-
Install software only from official sources; avoid cracks and “free” codecs.
-
Keep OS, browsers, and plugins patched; block macros by default.
-
Use reputable EDR/anti-malware and email/web filtering.
Downloader, dropper, and payload
A downloader needs a network connection to fetch another component. A dropper already carries or reconstructs its payload locally. Attackers may combine both techniques, and the downloaded payload can be ransomware, spyware, a remote-access tool, or another loader.
Check for secondary infection
- Isolate the device if it contacted an unknown server or other computers show alerts.
- Run a complete scan, not only a scan of the initially detected file.
- Review startup entries, scheduled tasks, services, browser extensions, and recently created accounts.
- Install security updates and remove the application or document that delivered the trojan.
- If credential theft is possible, change passwords from a clean device and revoke active sessions.
Deleting the downloader is not enough when a payload has already run. For important or business systems, preserve evidence and rebuild the device when its integrity cannot be established.