Trojan

Trojan.Generic.11511205 removal tips

Malware Removal

The Trojan.Generic.11511205 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.11511205 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

lds.100bt.com
52lds.howbk.com
count.2881.com
www.2345.com
www.bing.com

How to determine Trojan.Generic.11511205?


File Info:

crc32: BEAE0C18
md5: aa6a4be0ca696aefd25358951a01c348
name: ldsfyf.exe
sha1: 55fc20bf44444891cf26c66d73d3acfc299998c1
sha256: 2c34c695c0047f4c135f8ea81cd54f39db3732f5f25cc9c9d7c232fd876505ee
sha512: 0626017ca953cbb46a752e78aa193895c3c65343a69c29dda2b3d5ff98553602fc426b80e4d130611a3c4fa6a23fa7ecdd24987186f311f8cfda882ad8515e4d
ssdeep: 49152:Nc1VX8+A9/kSg/FYTF7UPqDeqxGP5+FAAawXoLCe+s8KuqGaX0ToIBAUZLY8Km1:8h8+Afg/FY57UPW84Fn06JBAUZLV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x96e8x8fb0 x7248x6743x6240x6709
FileVersion: 2.4.0.0
CompanyName: x96e8x8fb0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x9f99 x6597 x58eb x98ce x4e91 x8f85 x52a9
ProductVersion: 2.4.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Trojan.Generic.11511205 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.Generic.11511205
FireEyeGeneric.mg.aa6a4be0ca696aef
Qihoo-360HEUR/QVM07.1.301D.Malware.Gen
McAfeeArtemis!AA6A4BE0CA69
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.Generic.11511205
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34104.it0@amibOlcH
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
GDataWin32.Application.PUPStudio.A
TencentWin32.Adware.Bp-traffic.Mwlf
Ad-AwareTrojan.Generic.11511205
SophosGeneric PUA FF (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Generic.11511205 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.CLL.gen!Eldorado
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.DAFA5A5
MicrosoftTrojan:Win32/Wacatac.C!ml
TotalDefenseWin32/Oflwr.A!crypt
Acronissuspicious
ALYacTrojan.Generic.11511205
VBA32BScope.Trojan.Downloader
RisingTrojan.Win32.Generic.17EBDB21 (C64:YzY0Onuk2t1UQjqm)
MAXmalware (ai score=87)
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.65CA!tr
Cybereasonmalicious.0ca696
Paloaltogeneric.ml
MaxSecureTrojan.Kolovorot.in

How to remove Trojan.Generic.11511205?

Trojan.Generic.11511205 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment