Malware

Generic.Starter.4.7CCE0A59 (file analysis)

Malware Removal

The Generic.Starter.4.7CCE0A59 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Starter.4.7CCE0A59 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task

How to determine Generic.Starter.4.7CCE0A59?


File Info:

name: 0022D479F04334C22EA1.mlw
path: /opt/CAPEv2/storage/binaries/d413ea49dd4aea9591c7c40b7e6c637161b868c1e43408d896c4c53914c35544
crc32: 91C77745
md5: 0022d479f04334c22ea1ba5629b8ef79
sha1: 141126e7714d7057ab0ebf025ab8a4c528bc676a
sha256: d413ea49dd4aea9591c7c40b7e6c637161b868c1e43408d896c4c53914c35544
sha512: ea04e1f4f21e5971d1aeb52fb3217fc755eb4b0534cd6f6c37cc14eb3c349ff16a20f774fbd5caa0b283cec070ca53a50ea5c552269de28ecd864bdada35844d
ssdeep: 196608:kK/nIKfijy3Z2TIX406CYlktAc136v4IYYKVUtrkbtZvC30KYEea4/71RN:dIKfimZc+4ryt53xYKW5kbz63QETkZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1C63300F7C68D72FAA109720E687F06E438BE18651E9E114B99BB2EFF355B0B901357
sha3_384: 353ef4161cd18f0a3e91a15392c1c498ccad008cc34e1ae835cda521d99e50aa1bef7d28dc3acb8a775b6db47fff0c48
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Generic.Starter.4.7CCE0A59 also known as:

BkavW32.AIDetectMalware
AVGWin32:Malware-gen
MicroWorld-eScanGeneric.Starter.4.7CCE0A59
FireEyeGeneric.Starter.4.7CCE0A59
SkyhighBehavesLike.Win32.Trojan.wc
McAfeeArtemis!0022D479F043
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Runner.Allf
ESET-NOD32BAT/Runner.GK
CynetMalicious (score: 99)
ClamAVWin.Trojan.Starter-9375192-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Starter.4.7CCE0A59
NANO-AntivirusTrojan.Win32.Runner.jtnjts
AvastWin32:Malware-gen
EmsisoftGeneric.Starter.4.7CCE0A59 (B)
F-SecureTrojan.TR/Runner.yngit
VIPREGeneric.Starter.4.7CCE0A59
SophosMal/Generic-S
GDataGeneric.Starter.4.7CCE0A59
AviraTR/Runner.yngit
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGeneric.Starter.4.7CCE0A59
VBA32Trojan.Wacatac
Cylanceunsafe
MaxSecureTrojan.Malware.7164915.susgen
DeepInstinctMALICIOUS

How to remove Generic.Starter.4.7CCE0A59?

Generic.Starter.4.7CCE0A59 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment