Trojan

Trojan.Generic.1438850 malicious file

Malware Removal

The Trojan.Generic.1438850 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.1438850 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
autoupdate.ansav.com
www.hugedomains.com
ocsp.digicert.com

How to determine Trojan.Generic.1438850?


File Info:

crc32: D0853461
md5: 29178c83230fa4dc380589954a11a785
name: 29178C83230FA4DC380589954A11A785.mlw
sha1: f41032d669bd3e7e8cb8c72dfaaf2e279caa9b15
sha256: 619f15e1575ac01427d2dac4a301bb10e71760fc4b333d12c75dface4e389ba4
sha512: 81ab5f4c2fdd0fe8a4d0e796c5583d7591dd44c66d1e6f1093b78bd774ab2893e3633763405da0980453fbe3b9af065676088a8af33db0c533b4e4218dfd34f1
ssdeep: 3072:vO14akYNfHSmS9uNRul5N5cG9GytR3XnKOd9BWLHzZskpZuNVjeMPd3d:G14akYNRSQ69vRnKOd9ULH1JQWSd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006-2007, An Software Lab.
InternalName: ANSAV
FileVersion: 1.7.8
CompanyName: An Software Lab.
Author: 4NV|e
ProductName: ANSAV (An's Antivirus)
Contact: e-mail: anvie_2194@yahoo.com anvie@ansav.com
ProductVersion: 1.7.8
FileDescription: Mini Windows portable Antivirus
Home: http://www.ansav.com
OriginalFilename: ANSAV32.EXE
Translation: 0x0409 0x04b0

Trojan.Generic.1438850 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
ALYacTrojan.Generic.1438850
CylanceUnsafe
SangforTrojan.Win32.Orsam.rts
BitDefenderTrojan.Generic.1438850
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.ifzd
AlibabaRansom:Win32/Blocker.362b9448
MicroWorld-eScanTrojan.Generic.1438850
TencentWin32.Trojan.Blocker.Hprz
Ad-AwareTrojan.Generic.1438850
ComodoMalware@#1wtgtwfdys9ct
BitDefenderThetaGen:NN.ZexaF.34104.ji1aaK0ZQvni
VIPREBehavesLike.Win32.Malware.wlk (mx-v)
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeTrojan.Generic.1438850
EmsisoftTrojan.Generic.1438850 (B)
SentinelOneStatic AI – Suspicious PE
ArcabitTrojan.Generic.D15F482
ZoneAlarmTrojan-Ransom.Win32.Blocker.ifzd
GDataTrojan.Generic.1438850
McAfeeArtemis!29178C83230F
MAXmalware (ai score=99)
MalwarebytesMalware.Heuristic.1001
YandexTrojan.Blocker!SDKUlQS1Wc0
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Malware_fam.NB
PandaTrj/CI.A

How to remove Trojan.Generic.1438850?

Trojan.Generic.1438850 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment