Trojan

About “Trojan.Generic.1749648” infection

Malware Removal

The Trojan.Generic.1749648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.1749648 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Trojan.Generic.1749648?


File Info:

name: 62BC760AFDF52A8BA492.mlw
path: /opt/CAPEv2/storage/binaries/89b3a203fafc1319b6dd04dd27e5071bfe71e2150f2b02eb208f522e990d7197
crc32: 0D31D856
md5: 62bc760afdf52a8ba4925fbc18f576dc
sha1: 2c2b0505537226f5dc9769f11e5009f5cc45d6b8
sha256: 89b3a203fafc1319b6dd04dd27e5071bfe71e2150f2b02eb208f522e990d7197
sha512: a70056fe738b5d8663c962386022e51eeb686674c1f24c4cafed5dd3658106c16d697a021b15118626b873281df9c223383dfb7a732b574802dc80d82e5591b8
ssdeep: 1536:p4q8Q1xZtffrb8sjPFNhTYsFFrzckH2fmit3VtE/KfSFUf:qKtfDwsjPThTYszDH2fNVtE/yS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5739F57FE9388B2E02505B86D14C6C6F6BA76303E1A456F76ED8E0CDE563C2111C2B7
sha3_384: d1378838e9c36f2e11b73441a4b34d039922854d9038f5ca474493bda15dd22268f5c92b191c8452d2942dc61b74fe2a
ep_bytes: 558bec83c4e8535633c08945e88945ec
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Generic.1749648 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.1749648
FireEyeGeneric.mg.62bc760afdf52a8b
CAT-QuickHealW32.Viking.G8
McAfeePWS-LegMir.j.gen
CylanceUnsafe
VIPREVirus.Win32.Viking.ms (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005788931 )
K7GWTrojan ( 005788931 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Viking.d
CyrenW32/Legendmir.GBCN-2869
SymantecW32.Looked.F
ESET-NOD32Win32/PSW.Legendmir.XE
APEXMalicious
ClamAVWin.Trojan.Delf-1564
KasperskyVirus.Win32.Lamer.xe
BitDefenderTrojan.Generic.1749648
NANO-AntivirusTrojan.Win32.Lmir.kjsx
SUPERAntiSpywareTrojan.Agent/Gen-GameThief
AvastWin32:Lmir-FX [Trj]
RisingVirus.Win32.Autorun.bl (CLASSIC)
Ad-AwareTrojan.Generic.1749648
SophosML/PE-A + W32/LegMir-T
ComodoTrojWare.Win32.PSW.Legendmir.XE@1dov
DrWebWin32.HLLW.Lant
ZillyaTrojan.Lmir.Win32.3
TrendMicroPE_LEGMIR.D
McAfee-GW-EditionBehavesLike.Win32.Ipamor.lh
EmsisoftTrojan.Generic.1749648 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.1749648
JiangminTrojan/PSW.LMir.avh
eGambitUnsafe.AI_Score_99%
AviraW32/Lemir.Dll.1
Antiy-AVLTrojan/Generic.ASBOL.B8DE
ArcabitTrojan.Generic.D1AB290
ViRobotWin32.Lmir.59904
MicrosoftVirus:Win32/Viking.MS
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.59904
Acronissuspicious
BitDefenderThetaAI:Packer.C3E9286C16
ALYacTrojan.Generic.1749648
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Mokes
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallPE_LEGMIR.D
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!S1dREYVu8UQ
FortinetW32/LEGMIR.DO!tr
AVGWin32:Lmir-FX [Trj]
Cybereasonmalicious.afdf52
PandaW32/Legmir.BC

How to remove Trojan.Generic.1749648?

Trojan.Generic.1749648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment