Trojan

Trojan.Generic.11627850 removal tips

Malware Removal

The Trojan.Generic.11627850 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.11627850 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Generic.11627850?


File Info:

name: 6AAC0819892081DA5785.mlw
path: /opt/CAPEv2/storage/binaries/8ab2de82b57f02cd4bec0d774e1169e7bfe72721ceea3cd171ccff2a593e524a
crc32: B27184DB
md5: 6aac0819892081da5785eec494bdab63
sha1: 819c39bca2bb35363df4ea3c51384664eecf828a
sha256: 8ab2de82b57f02cd4bec0d774e1169e7bfe72721ceea3cd171ccff2a593e524a
sha512: aa56d9db96ee3d126f6f77406104c26b8bea979a9027a500566b7041cb889ab3f116d635ebe080c75f1368a54c2b8cc7c6a309a379cea6d2fbbc62d9c3ce2fee
ssdeep: 196608:sXK+SkvnpGt/E1pJ1ahAHSUwen/dhSBvC1zPOMD5W9YxzNrsr9IzttVXhI+y7:M3pRrIAHCqdhSB+zPOM4Y3vtTq+Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193C62353A39C8C27C6D10B796C92DB7060E85E302197160DE5E6EE7F74AB311879CF8A
sha3_384: ebdcddd6b514b1cfb399320f660b57442a382972051cb48d2b473025445e9821f3eea62327d79ca1ba77b22c58bc830d
ep_bytes: e8e3feffff33c050505050e8f22d0000
timestamp: 2012-02-17 14:55:21

Version Info:

0: [No Data]

Trojan.Generic.11627850 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Generic.11627850
McAfeeArtemis!6AAC08198920
MalwarebytesGeneric.Malware/Suspicious
K7AntiVirusAdware ( 004db9a51 )
K7GWAdware ( 004db9a51 )
Cybereasonmalicious.989208
VirITBackdoor.Win32.Agent.ANYS
ESET-NOD32multiple detections
ClamAVWin.Trojan.693223-1
BitDefenderTrojan.Generic.11627850
NANO-AntivirusTrojan.Win32.RiskGen.bofvsu
EmsisoftTrojan.Generic.11627850 (B)
VIPRETrojan.Generic.11627850
TrendMicroADW_CLICKER
Trapminesuspicious.low.ml.score
FireEyeTrojan.Generic.11627850
SophosGeneric Reputation PUA (PUA)
GDataTrojan.Generic.11627850
JiangminDangerousObject.Multi.ibh
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.SGeneric
GridinsoftTrojan.Win32.Agent.sa
XcitiumMalware@#jz3ybho6zyux
ArcabitTrojan.Generic.DB16D4A [many]
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGen:Variant.Johnnie.297063
Cylanceunsafe
TrendMicro-HouseCallADW_CLICKER
RisingTrojan.Zpevdo!8.F912 (CLOUD)
YandexRiskware.Agent!EVSyPfaENZ8
IkarusBackdoor.Win32.Agent
FortinetRiskware/Opiker
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Trojan.Generic.11627850?

Trojan.Generic.11627850 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment