Trojan

About “Trojan.Generic.22686073” infection

Malware Removal

The Trojan.Generic.22686073 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22686073 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Trojan.Generic.22686073?


File Info:

crc32: 5853A438
md5: b06df005b3fad17bf39cce462b597b1a
name: B06DF005B3FAD17BF39CCE462B597B1A.mlw
sha1: 42105bc37f50459fed081383c4e8e831ce4f90b3
sha256: 627298fe6229a8b13445833a2a4b4d6a959984a160801db839f8ed793021a9ec
sha512: 60179d2b143b7d1bc024821db74b7acd262f25543deab6ab076b029a3c50805e0405501097b64c0428fe231ed1b51a0617b99da4a4d820ddf2d2b7a209d11558
ssdeep: 3072:ysPfiBV9w2VjNudouqoAx2EfhCPYI5hJLsZTecTGKitV0JNtl7L:ysP6BTw2nudouqomsAIeZT9AVy3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Pks Pipi
InternalName: hurroosh
FileVersion: 8.9.0.12624
CompanyName: Pks Pipi
ProductName: hurroosh stond rin
ProductVersion: 8.9.0.12624
FileDescription: hurroosh compursion
OriginalFilename: hurroosh.exe
Translation: 0x0409 0x04b0

Trojan.Generic.22686073 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0048cbe01 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
ALYacTrojan.Generic.22686073
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.3930
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Generic.22686073
K7GWTrojan ( 0048cbe01 )
Cybereasonmalicious.5b3fad
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYLT
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Zerber.fikp
NANO-AntivirusTrojan.Win32.Zerber.evmsao
MicroWorld-eScanTrojan.Generic.22686073
TencentWin32.Trojan.Zerber.Pcsj
Ad-AwareTrojan.Generic.22686073
SophosMal/Generic-S
ComodoMalware@#2tz2gypna6eeu
BitDefenderThetaGen:NN.ZevbaF.34796.kq0@amXehufi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GIX!B06DF005B3FA
FireEyeGeneric.mg.b06df005b3fad17b
EmsisoftTrojan.Generic.22686073 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1121409
Antiy-AVLTrojan/Generic.ASMalwS.22DD77A
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Generic.D15A2979
GDataTrojan.Generic.22686073
Acronissuspicious
McAfeeRansomware-GIX!B06DF005B3FA
MAXmalware (ai score=99)
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.82 (RDML:yNWWfYG0ez3whRxxdQx8bA)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBEpsA

How to remove Trojan.Generic.22686073?

Trojan.Generic.22686073 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment