TrojanDownloader:HTML/Adodb.gen!A – malware that typically resides in Discord cache folder

TrojanDownloader:HTML/Adodb.gen!A is a detection name that you can encounter at any time when your computer is running. This type of malware can be encountered as a script that affects the way browsers operate. Many users have complained about Windows Defender or another security software flagging this malware on their computers, and the detected file was located in the following location:
C:\Users\AppData\Roaming\discord\Cache\
Allegedly, the detection is related to a Discord picture file that has been sent around the web. Users who downloaded suspicious files said they received a pop-up message from their security tools. Since TrojanDownloader:HTML/Adodb.gen!A is a generic detection name, it might be a false-positive, but you should always investigate before making decisions.
| Name | TrojanDownloader:HTML/Adodb.gen!A |
| Type | Malware |
| Distribution | This particular malware was found being distributed via communication platform Discord |
| Threat location | C:\Users\AppData\Roaming\discord\Cache\ |
| Symptoms | Detection from security software is the only symptom you might experience |
| Capabilities | By using the malicious script, malware authors could escalate their privileges and execute malicious code on the host device |
| Related | TrojanDownloader.VBS.Agent, Trojan.Downloader, TrojanDownloader:PowerShell/Falsip.A |
| Elimination | To ensure that the threat is not a false positive, you should perform a system scan with alternative security software. In case the file is flagged once again – eliminate it immediately |
| System fix | Malware infections can diminish the performance of your computer or cause serious stability issues. Use FortectIntego to remediate your device and ensure that the virus damage is fixed |
TrojanDownloader:HTML/Adodb.gen!A is generally an HTML script – a piece of code that can be executed when certain conditions are met. It means that this code might run on the targeted system without the installation of malicious software. This can be particularly dangerous, as security software might fail to detect such behavior.
HTML is a programming language that is often used within a browser environment, and pieces of code can be found on every visited website. However, it can also be used for malicious purposes and, once executed, might be exploited by cybercriminals. Other similar scripts that can be used for malware are:
- VBS (Visual Basic)
- JavaScript.
By using this Trojan, threat actors would be able to execute malicious code on the targeted machine. Consequently, they could initiate actions that benefit them,
Users can encounter the TrojanDownloader:HTML/Adodb.gen!A virus after downloading a picture sent via Discord communication app. This software is extremely prevalent, with millions of users worldwide – it is especially popular within the gaming community.
However, malware authors can often abuse the platform for malicious intent to spread Discord viruses around. In fact, this is not the first time that the app was used to deliver malicious files or links that would allow scamming users in various ways. Previously, threat actors were distributing Spidey Bot to steal users' personal information.
When talking of this particular Trojan capabilities, it could allow the attackers to do the same. It could also result in the infiltration of other malware, such as backdoors or ransomware. The latter is particularly dangerous, as it could result in a complete data loss. This is why a timely TrojanDownloader:HTML/Adodb.gen!A removal is so important.
Since the malware is running based on HTML script, it is likely to affect various browsers, including Google Chrome, Mozilla Firefox, Safari, MS Edge, etc. For example, it could be employed by threat actors to steal all the information typed into them. As a result, users could suffer from serious privacy issues or even experience and identity theft.
Luckily, it is unlikely that this malware can actually cause any harm, at least not when security software flags it. Thus, if you saw this threat is detected on your device, you should not ignore it and remove TrojanDownloader:HTML/Adodb.gen!A by sending it to quarantine immediately and deleting all the related files.
If you have any doubts and have reason to believe that the detection is a false positive, you can always perform an additional scan with alternative security software, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. To fix virus damage, if such has occurred, we highly recommend using FortectIntego.

Discord is one of many platforms used by criminals to deliver malware
Communication platforms are extremely popular nowadays, as people use them to send private messages, videos, music, and another type of multimedia. Discord is one of the most popular VoIP platforms currently and is especially beloved by gaming and a few other communities. Unfortunately, the prevalence of such apps is constantly being abused by malicious actors, as they use these platforms to deliver malware and scam users into disclosing their personal information.
Therefore, it is always important to know that the communication platforms can be, and will be, used to deliver malicious programs or scripts. To avoid such situations, you should always be aware that a direct message (DM) from an unknown individual should never be trusted. It is important not to click on links that could redirect to spoofing or boobytrapped websites.
In case there is no security software installed, malware could be executed immediately. In some cases, avoiding links might not always be possible, hence you need to employ additional precautions:
- keep an up-to-date security tool running at all times
- patch all the software on your machine with the latest updates.
TrojanDownloader:HTML/Adodb.gen!A removal process
As evident, if you have robust security software installed, you should remove TrojanDownloader:HTML/Adodb.gen!A as soon as it is flagged. This is especially important if you have recently clicked on a seemingly innocent link or downloaded a picture or another file to your computer via the Discord app. If not taken care of, the threat could lead to remote code execution by the attackers, who could technically install anything in your machine without you knowing.
If your security software is incapable of performing a permanent TrojanDownloader:HTML/Adodb.gen!A removal (for example, the identification shows up every time) you should perform a full system scan with security software, such as SpyHunterCombo Cleaner. Since the malicious script is written in HTML, it is also important to clean all your web browsers to ensure that no leftovers are present on the device. If the virus managed to break into your device already, you should eliminate it and then scan it with PC repair tool FortectIntego for best results.
Reset Internet Explorer
Remove dangerous add-ons:
- Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
- Pick Manage Add-ons.
- You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

Change your homepage if it was altered:
- Open IE and click on the Gear icon.
- Select Internet Options.
- In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
- Click Apply and then select OK.

Delete temporary files:
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.

Reset Internet Explorer:
- Click on Gear icon > Internet options and select Advanced tab.
- Select Reset.
- In the new window, check Delete personal settings and select Reset.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Instructions for Chromium-based Edge
Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Did this guide help?
Be the first to comment