Malware

Malware.Generic.CN1 (A) removal

Malware Removal

The Malware.Generic.CN1 (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Generic.CN1 (A) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

4.top4top.net

How to determine Malware.Generic.CN1 (A)?


File Info:

crc32: 10F8D58A
md5: 0ce741e8a6c7bba88c69cc71330f4170
name: stev.exe
sha1: 63eee1f07e4a4ab96a98a04f27de325e30015c1c
sha256: 697b92f295dd3478b75913caf2937eeb4adbbbd339aeb5e40c775b0053bec139
sha512: 46cac4f7785ed08afe4400c01130e90a31b4656bc46616f02c3224871bc55242f198cea532c6c0a8daf846e9259129da9551bbead09b0a8eaf422ae27b07adfc
ssdeep: 3072:Aa/HGvP90/KLNvir9R92YZadlWz8baRYXlEtancRu7YHSfZEPCp3j2BMshKKQ1+:fHGvPG4xijzswODHGvPG4xiSZLDZbPO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: MFC140ITA.DLL
FileVersion: 14.23.27820.0 built by: vcwrkspc
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Visual Studioxae 2017
ProductVersion: 14.23.27820.0
FileDescription: MFC Language Specific Resources
OriginalFilename: MFC140ITA.DLL
Translation: 0x0409 0x04b0

Malware.Generic.CN1 (A) also known as:

DrWebTrojan.MulDrop11.29958
MicroWorld-eScanTrojan.GenericKD.32767553
McAfeeArtemis!0CE741E8A6C7
MalwarebytesTrojan.PowerShellSP.MSIL
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0050e10f1 )
BitDefenderTrojan.GenericKD.32767553
K7GWTrojan ( 0050e10f1 )
Cybereasonmalicious.07e4a4
BitDefenderThetaGen:NN.ZemsilF.32517.Hq0@aWn4mqgG
F-ProtW32/Injector.HH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.BSG
APEXMalicious
GDataTrojan.GenericKD.32767553
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
AlibabaTrojan:MSIL/GenKryptik.cf3ece6c
AegisLabTrojan.MSIL.Dnoper.4!c
RisingDownloader.Agent!8.B23 (TOPIS:E0:oUC6QWzVLtG)
Ad-AwareTrojan.GenericKD.32767553
SophosMal/Generic-S
ComodoMalware@#1vtb06id07ovf
F-SecureTrojan.TR/Kryptik.czorr
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.0ce741e8a6c7bba8
EmsisoftMalware.Generic.CN1 (A)
IkarusTrojan-Spy.MSIL
CyrenW32/Injector.HH.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/Kryptik.czorr
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F3FE41
ZoneAlarmHEUR:Trojan.MSIL.Dnoper.gen
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Malware/Win32.RL_Generic.C3608046
CylanceUnsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R02FC0GL119
SentinelOneDFI – Malicious PE
FortinetMSIL/Agent.AFY!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.bdc

How to remove Malware.Generic.CN1 (A)?

Malware.Generic.CN1 (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment