Malware

Generic.TrickBot.2.11992452 malicious file

Malware Removal

The Generic.TrickBot.2.11992452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.TrickBot.2.11992452 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Created a service that was not started

How to determine Generic.TrickBot.2.11992452?


File Info:

crc32: 7F78C20C
md5: e225b045d1029c5150eaef1f55b6673e
name: E225B045D1029C5150EAEF1F55B6673E.mlw
sha1: 513b2942d041183f746201ff540625ae8b4595f9
sha256: f38b9f4aa29e63c72660936a845cfac204509e778188bcd81cfd2e76141a1d23
sha512: b2f208ad22ec2f4b444b2085829812e6918fc0330c566a048cd6f8f0dbc702ffe152ec78bccb41e0082852fc12bbc9c6bc1a8899fcbe15359a3c3f07b8b8b893
ssdeep: 6144:pfs/Wsohg6astcmGujoN0wwl0fir0yhzZ4eI1D52XIM0mvLpEN6rofW:pfs/WswilUZwsrV9OD52XIMxa6ofW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: WBP
FileVersion: 1, 0, 0, 1
ProductName: WBP Application
ProductVersion: 1, 0, 0, 1
FileDescription: WBP MFC Application
OriginalFilename: WBP.EXE
Translation: 0x0409 0x04b0

Generic.TrickBot.2.11992452 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.TrickBot.2.11992452
FireEyeGeneric.mg.e225b045d1029c51
ALYacDeepScan:Generic.TrickBot.2.11992452
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056060e1 )
BitDefenderDeepScan:Generic.TrickBot.2.11992452
K7GWTrojan ( 0056060e1 )
TrendMicroTrojanSpy.Win32.EMOTET.SMC3
CyrenW32/Agent.BJX.gen!Eldorado
SymantecPacked.Generic.534
APEXMalicious
ClamAVWin.Dropper.Emotet-7534606-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
NANO-AntivirusTrojan.Win32.Kryptik.gtwpgo
RisingTrojan.Generic@ML.100 (RDML:h4gq7YTn5eaG0PDnu3R2Ow)
Ad-AwareDeepScan:Generic.TrickBot.2.11992452
DrWebTrojan.Emotet.887
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Emotet.fh
EmsisoftTrojan.Emotet (A)
IkarusWorm.Win32.Stration
JiangminTrojan.Banker.Emotet.pjp
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitDeepScan:Generic.TrickBot.2.11992452
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataDeepScan:Generic.TrickBot.2.11992452
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R309540
McAfeeEmotet-FPC!E225B045D102
MAXmalware (ai score=89)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HAEJ
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMC3
FortinetW32/Kryptik.EEDP!tr
BitDefenderThetaGen:NN.ZexaF.34634.uq0@aOrRm8ai
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.2d0411
AvastWin32:BankerX-gen [Trj]
MaxSecureTrojan.Malware.121218.susgen

How to remove Generic.TrickBot.2.11992452?

Generic.TrickBot.2.11992452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment