Trojan

Trojan.Generic.22606187 malicious file

Malware Removal

The Trojan.Generic.22606187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22606187 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects the presence of Wine emulator via function name
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects information about installed applications
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

daub.unnotable.ru
ec2-54-154-5-3.eu-west-1.compute.amazonaws.com

How to determine Trojan.Generic.22606187?


File Info:

crc32: C73CF141
md5: fced4602121409c5c9393ad7c088e0d1
name: FCED4602121409C5C9393AD7C088E0D1.mlw
sha1: d486b02f8501bb5a7fb298debca6b6c42a73ecc6
sha256: d495e2bed98dfbadeda34516d50bebf02f6132addd64a5ed87d5eda91bdf7cdb
sha512: d4282a90707d7001fb5880928b4ddfc61bac06c7dfc376972213dfb30c6363d93971ecabb15c0ed3ddabfdabe76a685a187bc88f98994eeaf9694c0a24f1f171
ssdeep: 49152:Wkv1TzoxZbnBESDSgHg6RKPu6z6rPpNuAx6RU3cbn3MBG440J3me4M:Wkl+BESTA6UPBAx6kEn820
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Generic.22606187 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2259
MicroWorld-eScanTrojan.Generic.22606187
FireEyeGeneric.mg.fced4602121409c5
CAT-QuickHealSoftwareBundler.InstallMonster
McAfeeArtemis!FCED46021214
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0053082d1 )
BitDefenderTrojan.Generic.22606187
K7GWAdware ( 0053082d1 )
Cybereasonmalicious.212140
BitDefenderThetaGen:NN.ZelphiF.34804.voHfamAf4Rhi
CyrenW32/InstallMonster.JJ.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallHT_INSTALLMONSTR_GJ30005A.UVPM
AvastWin32:PUP-gen [PUP]
ClamAVWin.Malware.Agent-6598770-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaTrojan:Win32/InstallMonstr.ad8c40b3
NANO-AntivirusTrojan.Win32.InstallMonster.euowbz
RisingTrojan.FakeAV!8.175 (CLOUD)
Ad-AwareTrojan.Generic.22606187
SophosInstall Monster (PUA)
ComodoApplication.Win32.InstallMonster.TN@7g2wfa
F-SecureHeuristic.HEUR/AGEN.1116974
ZillyaAdware.InstMonster.Win32.167
TrendMicroHT_INSTALLMONSTR_GJ30005A.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE – Installer
EmsisoftTrojan.Generic.22606187 (B)
Ikarusnot-a-virus:AdWare.InstallMonster
JiangminTrojan.Fakeav.btq
eGambitUnsafe.AI_Score_98%
AviraHEUR/AGEN.1116974
Antiy-AVLTrojan[Packed]/Win32.Dico
MicrosoftSoftwareBundler:Win32/InstallMonster
GridinsoftAdware.Win32.BundleInstaller.oa
ArcabitTrojan.Generic.D158F16B
ZoneAlarmPacked.Win32.Dico.gen
GDataWin32.Application.InstallMonstr.V
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.InstallMonster.R212027
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.Generic.22606187
MAXmalware (ai score=100)
MalwarebytesInstallMonster.Adware.Bundler.DDS
APEXMalicious
ESET-NOD32a variant of Win32/InstallMonstr.HI potentially unwanted
TencentMalware.Win32.Gencirc.10b392b1
YandexTrojan.GenAsa!M6pEafVvRIU
FortinetW32/Agen.AAAF!tr
AVGWin32:PUP-gen [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Virus.Adware.992

How to remove Trojan.Generic.22606187?

Trojan.Generic.22606187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment