Trojan

What is “Trojan.AllGen”?

Malware Removal

The Trojan.AllGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AllGen virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.AllGen?


File Info:

crc32: 04FB8B20
md5: 41942c999b708db08d97a52a4350a087
name: 41942C999B708DB08D97A52A4350A087.mlw
sha1: 9e9228127a721febaabf344f04f4ca0ea8861b13
sha256: 2d1e3062e813ed6cfaeb89f3327444d8f0fd2330818863997e25f9256f17886c
sha512: aa9eae9bb8442074aa7dc82cc24e7fe4816a8367dc0570799c9cb7d2d348678aaa17f8a7373cba78478a5c1c529d75bbbf85de4f1dc3c90c50e74f1177872fbd
ssdeep: 6144:O1apbL/v14VDzqAZIgY1WCBARTCgbDPcQ:O1OLqzji3BSbA
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0416 0x04e4

Trojan.AllGen also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Delf.Inject.Z
ALYacTrojan.Delf.Inject.Z
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderTrojan.Delf.Inject.Z
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.99b708
BitDefenderThetaAI:Packer.B2C09FCA21
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirTool:Win32/DelfInject.b2213f3c
NANO-AntivirusTrojan.Win32.Sasfis.davwjf
ViRobotTrojan.Win32.Z.Banker.239616.J
AegisLabTrojan.Win32.Generic.lvC2
TencentWin32.Trojan.Invader.Pbpc
Ad-AwareTrojan.Delf.Inject.Z
EmsisoftTrojan.Delf.Inject.Z (B)
ComodoMalware@#11nhfxbwqyb3z
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.DownLoader5.50033
ZillyaTrojan.Banker.Win32.56541
TrendMicroTROJ_GEN.R03BC0CLL20
McAfee-GW-EditionBehavesLike.Win32.Injector.dc
FireEyeGeneric.mg.41942c999b708db0
SophosMal/Generic-S
IkarusTrojan-PWS.Banker6
JiangminTrojan/Sasfis.zwb
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Delf.Inject.Z
SUPERAntiSpywareTrojan.Agent/Gen-Banker
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Delf.Inject.Z
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Delfinject.643584
McAfeeArtemis!41942C999B70
MAXmalware (ai score=100)
VBA32BScope.Adware.DealPly
MalwarebytesTrojan.AllGen
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.Banker.WTP
TrendMicro-HouseCallTROJ_GEN.R03BC0CLL20
YandexTrojanSpy.Banker!3lb7kJAhpOA
SentinelOneStatic AI – Malicious PE – Adware
eGambitUnsafe.AI_Score_100%
FortinetW32/Sasfis.CZB!tr
WebrootW32.Malware.Gen
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM11.1.Malware.Gen

How to remove Trojan.AllGen?

Trojan.AllGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment