Trojan

Trojan.Generic.21467937 (file analysis)

Malware Removal

The Trojan.Generic.21467937 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.21467937 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Generic.21467937?


File Info:

name: 180A1F3F30188FF42D5E.mlw
path: /opt/CAPEv2/storage/binaries/b1d3096ce758c1f5846ba539a56efa89842d115d2a38f6ae82e7223ce82257f4
crc32: 416FF7B5
md5: 180a1f3f30188ff42d5ed61479edb9e6
sha1: b15e8950d23e92a3f5f426dbb2a017dc0a50951c
sha256: b1d3096ce758c1f5846ba539a56efa89842d115d2a38f6ae82e7223ce82257f4
sha512: f9b7911dc2ffb151f33e53f9af7e1a26bfcc156e6563e7a9d521d408763e90897d5e5566ee75231ca3393d2d5134513cf763930090f3b709c61d895df852402a
ssdeep: 96:PFLkCWLYgH5H6QxPhihW+VpouLgZSOj1OtdKxBMbxf1cFQMFo8EhvonB4D:P6CWTZHhhiP4uwSO5OXKxBcF16Fo8Qo+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1ABC18EE1951D0DE7C86307F96A46902B91F3B808A3FE93909E6DB63CADF309D150568A
sha3_384: e00544577268a215fd00b10b9cec25d4e56a5e0e763cbdac1c1dda6c9e478067dc3451756cc864b6a9d266dca34dda15
ep_bytes: 60be15b040008dbeeb5fffff5783cdff
timestamp: 2017-01-06 18:50:47

Version Info:

0: [No Data]

Trojan.Generic.21467937 also known as:

MicroWorld-eScanTrojan.Generic.21467937
FireEyeGeneric.mg.180a1f3f30188ff4
ALYacTrojan.Generic.21467937
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
AlibabaTrojan:Win32/XPACK.bd161df2
Cybereasonmalicious.f30188
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
BitDefenderTrojan.Generic.21467937
NANO-AntivirusTrojan.Win32.Crypted.eqvecm
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.21467937
McAfee-GW-EditionBehavesLike.Win32.Downloader.xc
EmsisoftTrojan.Generic.21467937 (B)
GDataTrojan.Generic.21467937
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=87)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:MacOS/Ymacco.AA80
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C2133647
McAfeeArtemis!180A1F3F3018
VBA32BScope.Trojan.Packed
RisingMalware.Generic.5!tfe (CLOUD)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34638.amGfammECRd
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Generic.21467937?

Trojan.Generic.21467937 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment