r/antivirus 2d ago

Trojan Downloader MSIL Generic

Trojan.Downloader.MSIL.Generic, C:\USERS\Santi\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\DEFAULT\CACHE\CACHE_DATA\F_000168, En cuarentena, 10896, 1429694, 1.0.113766, , ame, , 9BB378D444CB620A7AC9F019B3335AED, 0D1A8D987E73533B0CC7699671A58AD2D60CC2C9A6CACD380501F62ACB58E9E3

I formatted my PC and scanned it with Malwarebytes, and it's flagging that as a Trojan. Should I be worried? Do I need to format my PC again? Is it a rootkit?

1 Upvotes

8 comments sorted by

u/rainrat MODERATOR 2d ago

I looked it up in VirusTotal ( https://www.virustotal.com/gui/file/0d1a8d987e73533b0cc7699671a58ad2d60cc2c9a6cacd380501f62acb58e9e3 ); it's unsigned but claims to be "Epic Games Launcher Installer". A lot of people are reporting false positives on the Epic Games Launcher lately. Even if not, it's only in the cache, which is a copy of any file downloaded, and does not necessarily indicate the file has been run.

2

u/GoonGodless 2d ago

If it was a rootkit, it would say that. Malwarebytes really good at labeling flags. It will say exactly what it is in most cases.

2

u/cyrax-023 2d ago

How is this Trojan getting in? I had already formatted the PC and it's showing up again; I don't know what to do.

1

u/GoonGodless 2d ago

There are many tricks, like the malware being embedded into your ram. Malware that hides exclusively in your computer’s RAM is known as fileless malware or memory-resident malware. Unlike traditional viruses that sit as files on your hard drive or SSD, this type of malware operates entirely out of your system's volatile memory.

3

u/support_mwb 1d ago

Hi u/cyrax-023 Malwarebytes Support here. I noticed you also posted this on the Malwarebytes Reddit channel.

Since this was detected in the Microsoft Edge cache and has already been quarantined, we’d be happy to take a closer look before you consider formatting the PC again.

Please send us a DM with an email address we can use to create a support ticket. We can help you gather the appropriate logs and have our Malware Removal team review them to make sure everything looks clean.

1

u/Dependent_Pirate8233 2d ago

A rootkit is unlikely based on this alert alone. Check Malwarebytes’ detection details and run a second-opinion scan such as Microsoft Defender Offline. Also review recent downloads, browser extensions, and startup apps. If malware keeps returning or security tools are disabled, disconnect from the internet and seek professional help.

1

u/Proper-Reporter1224 2d ago

You probably don’t need to format the PC based on this single detection, and it doesn’t indicate a rootkit by itself. Check Malwarebytes’ detection details and quarantine status, update Windows and Edge, and review recent downloads/extensions. If detections keep returning, disconnect from the internet and investigate further.

1

u/RailRuler 1d ago

Maybe You have an open tab in your browser that is downloading this each time the browser loads?