Trojan

Trojan.Generic.12199720 removal guide

Malware Removal

The Trojan.Generic.12199720 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.12199720 virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Generic.12199720?


File Info:

crc32: 952ACF05
md5: 24b316c9e346db036c1b17cf8911db79
name: This.War.of.Mine.All.Versions.tr4-XiaoXing.exe
sha1: d12ecd7c09a4d51cfe7531b4b343a7a6b73e0274
sha256: ac7dc73a46ef84787707cf27eeed185b5dbb1ce36e97dd723a68cf4aead7e565
sha512: 5932c2516e01b020522d6f7fad2dd2a59c499491faf63cfd49d906a3b91fc0a9366eb7f4bd5f7b3e4a547a0d28c0deb73483007349383445c02fd0f9906458ec
ssdeep: 6144:Opgocf4KQArIvg5oS7BQh7A5jymKWu0CNFM3PjoWaYA8MFnyFy+E3B+Ib9yx617H:OpT3KQCyV7CjymKxZCQ1Cy+a+FSbQ1C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: @x5c0fx5e78x59d0(Sachiko) x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: @x5c0fx5e78x59d0(Sachiko)
Comments: x5c0fx5e78x59d0x7684x5faex535a http://weibo.com/gggggg
ProductName: x8fd9x662fx6211x7684x6218x4e89 x4feex6539x5668
ProductVersion: 1.0.0.0
FileDescription: This War of Mine Trainer
Translation: 0x0804 0x04b0

Trojan.Generic.12199720 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.Generic.12199720
McAfeeGenericRXEU-WF!24B316C9E346
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.Generic.12199720
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.DBA2728
BitDefenderThetaGen:NN.ZexaF.34096.0q0@a8zXzckb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
ClamAVWin.Malware.Zusy-6840460-0
KasperskyTrojan-Spy.Win32.KeyLogger.bkzq
NANO-AntivirusTrojan.Win32.FlyStudio.fccuhn
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Wacatac!8.10C01 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Generic.12199720 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan:W32/DelfInject.R
ZillyaTrojan.Keylogger.Win32.10
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SentinelOneDFI – Malicious PE
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.24b316c9e346db03
SophosGeneric PUA NB (PUA)
APEXMalicious
F-ProtW32/Agent.EW.gen!Eldorado
JiangminTrojan.Generic.gfak
eGambitUnsafe.AI_Score_99%
FortinetW32/FlyStudio_HackTool.A!tr
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmTrojan-Spy.Win32.KeyLogger.bkzq
Acronissuspicious
VBA32BScope.Trojan.Orsam
ALYacTrojan.Generic.12199720
MAXmalware (ai score=81)
Ad-AwareTrojan.Generic.12199720
PandaTrj/GdSda.A
TencentWin32.Trojan-spy.Keylogger.Hrpb
IkarusTrojan-PSW.QQTen
GDataWin32.Application.FlyStudio.F
WebrootPua.Gen
Cybereasonmalicious.9e346d

How to remove Trojan.Generic.12199720?

Trojan.Generic.12199720 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment