Trojan

What is “Trojan.Generic.21067663”?

Malware Removal

The Trojan.Generic.21067663 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.21067663 virus can do?

  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan.Generic.21067663?


File Info:

name: 3153E1D495262C73BE83.mlw
path: /opt/CAPEv2/storage/binaries/3914be7fc4817d7b7c5a3187f226c4968f2bc000fe0807e5043764cda6828d16
crc32: F147735C
md5: 3153e1d495262c73be835bccd5f6c4b6
sha1: 433053a14980af36b0a74fab64e93a4d600f212c
sha256: 3914be7fc4817d7b7c5a3187f226c4968f2bc000fe0807e5043764cda6828d16
sha512: 4146b1ac72e42a7b6d6ed9757d58960bbc26e88287a75f471d6e14eeeeeff632bab09eee5a65a813add609da64216c94cddd55938e9385211da43554056bbe8f
ssdeep: 49152:JKiC/rk62xWNol+5gOsLO66qJ6021cJjLtk4pWGNG5VGFPNqJyoTL:KrZ23AbsK6Ro022JjL2WEiVqJZL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEC533450756A909E024017D9C832B9A3D67A4657F37AFB7A5CB042C6D38382FD2AF4F
sha3_384: b73d5fc868018ad6d638e0974c53930865a4d07a5dded7e764d43e2a0ef9401559c67fb9b71c23017358b1c605376fff
ep_bytes: e90afaffff558bec8b4508eb1780f93b
timestamp: 2004-11-11 21:11:30

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Update Package
FileVersion: 3.1
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SFXCAB.EXE
ProductName: MSI 3.1
ProductVersion: 3.1
Build Date: 2004/12/06
Applies to: Windows 2000 Service Pack 3, Windows 2000 Service Pack 4, Windows XP, Windows XP Service Pack 1, Windows XP Service Pack 2, Windows 2003
Installation Type: Full
Installer Version: 6.1.22.0
Installer Engine: update.exe
KB Article Number: 884016
Support Link: "http://go.microsoft.com/fwlink/?LinkId=33342"
Package Type: update
Proc. Architecture: x86
Self-Extractor Version: SFXCAB v6.1.6.0
Translation: 0x0000 0x04b0

Trojan.Generic.21067663 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop2.28272
MicroWorld-eScanTrojan.Generic.21067663
ALYacTrojan.Generic.21067663
CylanceUnsafe
Cybereasonmalicious.495262
ArcabitTrojan.Generic.D141778F
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Generic.21067663
Ad-AwareTrojan.Generic.21067663
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.vc
FireEyeTrojan.Generic.21067663
EmsisoftTrojan.Generic.21067663 (B)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftVirus:Win32/Occamy.C
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Virus.Patched.L@susp
Acronissuspicious
McAfeeArtemis!3153E1D49526
YandexTrojan.MulDrop!rF1GH0MkLA4
MAXmalware (ai score=80)
FortinetPossibleThreat
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Generic.21067663?

Trojan.Generic.21067663 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment