Trojan

About “Trojan.Generic.19749342” infection

Malware Removal

The Trojan.Generic.19749342 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.19749342 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bfgho.com
www.bing.com

How to determine Trojan.Generic.19749342?


File Info:

crc32: 36DCB49B
md5: 8c2384a5cc6b1454c5a53de1d356cc66
name: bfghost_7.0.exe
sha1: 6dadc75d69dcd841ee148c380d0e4dec278ee922
sha256: 4e525597c82e3c091f232471c6335e37d642d686b8b9d4a8918932e258461c60
sha512: b8212533dbcc4cc4f7b23b8ff43597b0342f379caa7847576e084745757bf1fbab77d0c5ad913f165902d6fe11078602687059aa6e89a2fe4695394b8260080d
ssdeep: 196608:VRnTM8akaYcJijRRSo/qlVOJf8bEcAMW4cWo7C0EH9C8+Rc5sO:VNw8akVcIjRMo/+VmoDW4NoGEy5sO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2005-2012 www.bfgho.com
FileVersion: 8.0.0.0
CompanyName: www.bfgho.com
x7f16x8bd1x5de5x5177: AuMFCompiler(x6807x51c6x7248)
LegalTrademarks: bfgho.com
ProductName: x51b0x5c01x4e00x952e
FileDescription: x51b0x5c01x4e00x952e
OriginalFilename: x51b0x5c01x4e00x952ex88c5x673a.exe
Translation: 0x0804 0x04b0

Trojan.Generic.19749342 also known as:

MicroWorld-eScanTrojan.Generic.19749342
McAfeeArtemis!8C2384A5CC6B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.Generic.19749342
Invinceaheuristic
F-ProtW32/Trojan2.NVGH
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-6651791-0
GDataTrojan.Generic.19749342 (2x)
KasperskyTrojan.Win32.Diztakun.atdb
AlibabaTrojan:Win32/Diztakun.49f0fd1f
AvastWin32:Evo-gen [Susp]
TencentWin32.Trojan.Palevo.Auto
Ad-AwareTrojan.Generic.19749342
DrWebTrojan.Siggen5.59949
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.wc
Trapminemalicious.moderate.ml.score
FireEyeTrojan.Generic.19749342
EmsisoftTrojan.Generic.19749342 (B)
IkarusVirus.Win32.Sality
CyrenW32/Trojan.IJBN-1595
WebrootW32.Trojan.GenKD
AviraTR/MultiInjector.nsanu
Antiy-AVLRiskWare/AU3.StartPage.a
ArcabitTrojan.Generic.D12D59DE
AegisLabTrojan.Win32.Diztakun.4!c
ZoneAlarmTrojan.Win32.Diztakun.atdb
MicrosoftTrojan:Win32/MultiInjector.C!rfn
VBA32Trojan.Diztakun
ALYacTrojan.Generic.19749342
MAXmalware (ai score=99)
RisingTrojan.Win32.Agent_.qo (CLASSIC:bWQ1OuhexUUfO6BOiB18tZmYGhI)
FortinetW32/StartPage.AIT!tr
MaxSecureTrojan.Malware.1728101.susgen
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.5cc6b1
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Generic.19749342?

Trojan.Generic.19749342 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment