Trojan

Should I remove “Trojan.Generic.15470487”?

Malware Removal

The Trojan.Generic.15470487 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.15470487 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.15470487?


File Info:

name: 9574FB1EA2876D12C85E.mlw
path: /opt/CAPEv2/storage/binaries/0a317b9a773970cb2af6afd94bc57554cbbda2d9f214ca0c6e75d05f12ab265a
crc32: A0DB01CC
md5: 9574fb1ea2876d12c85e7dca4216ba1d
sha1: 90ad88bef7381b7baea04526891e8ee2d71e48e7
sha256: 0a317b9a773970cb2af6afd94bc57554cbbda2d9f214ca0c6e75d05f12ab265a
sha512: b9848e79712258e4f20fa405dad1997d066f4f1e3115bbb7146d3625754b0a8d8224a0de1cec3673fe62ad037f5ee4c561d0546b242cfa4909615ba49793c48c
ssdeep: 49152:VQRfmjZ8JXJKezT2P4pdKTHnhrdR0W11N2h3+eUjC3D1YAhEnG7y:VQgos+pcTHJdR0W11N0xUjUZYIy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194A53349E782E595F09C113152CBABF4BB7A7E3BE4E6785FB3C2751A6A4110C0B41CB2
sha3_384: 1db0c67155536b5a6669dac8a04a58c84228fba0a6dcbb49c4347f1de38d28c0631ca5de8282ddc147f63dc17ea412c0
ep_bytes: 558bec6aff682821400068a01e400064
timestamp: 2011-01-31 17:44:13

Version Info:

0: [No Data]

Trojan.Generic.15470487 also known as:

LionicAdware.MSIL.Generic.2!c
MicroWorld-eScanTrojan.Generic.15470487
ALYacTrojan.Generic.15470487
CylanceUnsafe
SangforTrojan.Win32.Adload.8
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderTrojan.Generic.15470487
K7GWTrojan-Downloader ( 0055e3da1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Adload.NPA
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Generic
AlibabaAdWare:Win32/Adload.6e8e017a
NANO-AntivirusRiskware.Win32.Adload.dxzolx
TencentMsil.Adware.Generic.Htbw
Ad-AwareTrojan.Generic.15470487
SophosGeneric PUA JA (PUA)
ComodoMalware@#3mzta67mghk9
VIPREAdware.MSIL.Generic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeTrojan.Generic.15470487
EmsisoftTrojan.Generic.15470487 (B)
IkarusTrojan-Downloader.Win32.Adload
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.DEC0F97
GDataTrojan.Generic.15470487
McAfeeArtemis!9574FB1EA287
MalwarebytesPUP.Optional.OutBrowse
RisingTrojan.Generic@ML.87 (RDMK:vMMkCkH1r6bFtLtTvkXtzg)
FortinetAdware/Generic
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.ea2876
AvastWin32:Adware-gen [Adw]

How to remove Trojan.Generic.15470487?

Trojan.Generic.15470487 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment