Trojan

Should I remove “Trojan.Generic.20711199”?

Malware Removal

The Trojan.Generic.20711199 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.20711199 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

www.upload.ee
ocsp.digicert.com

How to determine Trojan.Generic.20711199?


File Info:

crc32: 0C9CBB42
md5: 399b78dbaddfe3cd5823f95b705ea132
name: 399B78DBADDFE3CD5823F95B705EA132.mlw
sha1: 2d46e3f097116b095b806d4d03db50b53ddc376b
sha256: b7c3b72caf3ad06f8c101c36f8076459a9f2ae9ebba329959679355d98c16827
sha512: a177b2a26aed312d211860877728359e2773c2606980c07de87e2d9b04834f494c21f9e4eade5c738c30ffd611c0d0b86737deb0926695eb4b2da53485a41146
ssdeep: 12288:jCdOy3vVrKxR5CXbNjAOxK/j2n+4YG/6c1mFFja3mXgcjfRlgsUBgaeTZOQ:jCdxte/80jYLT3U1jfsWaGZOQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Generic.20711199 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005156651 )
CynetMalicious (score: 99)
ALYacTrojan.Generic.20711199
CylanceUnsafe
K7GWTrojan ( 005156651 )
Cybereasonmalicious.baddfe
CyrenW32/AutoIt.GY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.ODS
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderTrojan.Generic.20711199
NANO-AntivirusTrojan.Win32.Mlw.elvyxx
MicroWorld-eScanTrojan.Generic.20711199
TencentWin32.Trojan.Generic.Llrn
Ad-AwareTrojan.Generic.20711199
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
FireEyeTrojan.Generic.20711199
EmsisoftTrojan.Generic.20711199 (B)
AviraHEUR/AGEN.1144389
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataTrojan.Generic.20711199
McAfeeArtemis!399B78DBADDF
MAXmalware (ai score=82)
PandaTrj/CI.A
IkarusTrojan-Downloader
FortinetW32/Autoit.ODS!tr.dldr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Generic.20711199?

Trojan.Generic.20711199 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment