Trojan

Trojan.Agent.TTWGen removal guide

Malware Removal

The Trojan.Agent.TTWGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.TTWGen virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.TTWGen?


File Info:

name: 096440800AE3ABC143E3.mlw
path: /opt/CAPEv2/storage/binaries/015cbb45e56d3bc0a4908b0b805da09d477e1696bb19323eb5493c3a9ddd3c5c
crc32: 29440059
md5: 096440800ae3abc143e382118731b40a
sha1: e4b8de5dbfe295986bde28b5b552a0f20097d8a4
sha256: 015cbb45e56d3bc0a4908b0b805da09d477e1696bb19323eb5493c3a9ddd3c5c
sha512: cc40fc0df0fc2f58098c24866a86a4bd42a0c68cf15704106f6f591a28d6cb603eb5f321c5ee381a16d41e9eb98ce30d8b30586a197ac67c0a8591258fde98f7
ssdeep: 12288:+k5L2FqP2Luuc3sZU9Vr0yiEDewok7SC2ED/lJLGa9R67mjey6Om8SzDP5:+2yQPp3mSfiEDok7SCh/527mjFlm8I5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EE402823784B8F5C6B1C532DF0DD77552B2E7E92B805E9B93822F062DD32A5620B1DD
sha3_384: 55329e48fcb97a11c50af38144d7011ee67bfe3ba567811393abedb26c3194f1b368c409e146cd522777a10470aaada1
ep_bytes: 558bec6aff68504c410068801f410064
timestamp: 2010-06-27 07:06:38

Version Info:

Comments:
CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX
FileVersion: 1, 2, 0, 715
InternalName: 7zSfxNew
LegalCopyright: Copyright © 2005-2007 Oleg N. Scherbakov
LegalTrademarks:
OriginalFilename: 7zSfxNew.exe
PrivateBuild: July 14, 2007
ProductName: 7ZSfxNew
ProductVersion: 1, 2, 0, 715
SpecialBuild:
Translation: 0x0000 0x04b0

Trojan.Agent.TTWGen also known as:

LionicTrojan.Win32.Badur.m658
MicroWorld-eScanTrojan.MCazm.Gen.1
FireEyeTrojan.MCazm.Gen.1
McAfeeArtemis!096440800AE3
CylanceUnsafe
SangforTrojan.Win32.MCazm.1
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Bicololo.8de41c82
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.00ae3a
SymantecTrojan.Gen
ESET-NOD32Win32/Bicololo.FX
APEXMalicious
ClamAVWin.Trojan.Bicololo-8
BitDefenderTrojan.MCazm.Gen.1
NANO-AntivirusTrojan.Win32.Qhost.dsoxej
SUPERAntiSpywareTrojan.Agent/Gen-Bicololo
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b40a7b
Ad-AwareTrojan.MCazm.Gen.1
SophosMal/Bicololo-A
TrendMicroTROJ_GEN.R002C0RD922
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
EmsisoftTrojan.MCazm.Gen.1 (B)
GDataTrojan.MCazm.Gen.1
ViRobotTrojan.Win32.Z.Bicololo.687593
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.MCazm.Gen.1
MAXmalware (ai score=81)
MalwarebytesTrojan.Agent.TTWGen
TrendMicro-HouseCallTROJ_GEN.R002C0RD922
FortinetW32/Bicololo.FX!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Agent.TTWGen?

Trojan.Agent.TTWGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment