Trojan

Should I remove “Trojan.Generic.22760067”?

Malware Removal

The Trojan.Generic.22760067 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22760067 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.22760067?


File Info:

crc32: 69A589D7
md5: cb72368fb134f3ac72e8fb13c47a9825
name: CB72368FB134F3AC72E8FB13C47A9825.mlw
sha1: 80f28905bcd979e8ad171ef0a436ee3d37da7916
sha256: cc31978c2c9f932fb6d23a72275acd97ec50f42ab773ee92fcf028a2d73983e8
sha512: de81c6507678b6ffac2ce8fc980a6de83b499ae3f1c713ad7e361a50a60420abf7baf9ff14a7114ee06865ca6056e57b9b34934958418d9e6adb8f7003a7319e
ssdeep: 1536:KVRhMtMQRqbZyQu0EpnWsjh1yR3aPc5AiHyAXLLSJBzdVbBwb4VE1ME+YIi0i9D:KJSM0mubWwaKPWSAn4xVbBw8jEzIDi9D
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: xa9 2016 VB6boost Dance
InternalName: VB6boost
FileVersion: 2.00
CompanyName: Booktopia
LegalTrademarks: stunning athleticism of ballet
ProductName: VB6boost
ProductVersion: 2.00
FileDescription: Browar and Ory's photos stand out is that they communicate
OriginalFilename: VB6boost.exe

Trojan.Generic.22760067 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052964f1 )
LionicTrojan.Win32.VBKrypt.mhnR
Elasticmalicious (high confidence)
DrWebTrojan.Kasidet.26
CynetMalicious (score: 100)
ALYacTrojan.Generic.22760067
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39475
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.c5e106f4
K7GWTrojan ( 0049c30b1 )
Cybereasonmalicious.fb134f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DUQR
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Trickbot-7648963-0
KasperskyTrojan-Ransom.Win32.Blocker.kmpr
BitDefenderTrojan.Generic.22760067
NANO-AntivirusTrojan.Win32.Blocker.ewgnbt
MicroWorld-eScanTrojan.Generic.22760067
TencentMalware.Win32.Gencirc.11494a19
Ad-AwareTrojan.Generic.22760067
SophosMal/Generic-S + Mal/Trickbot-E
ComodoMalware@#36n97o6pwn4yh
BitDefenderThetaGen:NN.ZevbaF.34110.gmuaaiUeyrFi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.cb72368fb134f3ac
EmsisoftTrojan.Generic.22760067 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.hzy
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Raybel.A!bit
ArcabitTrojan.Generic.D15B4A83
GDataTrojan.Generic.22760067
AhnLab-V3Trojan/Win32.Buzus.C146985
Acronissuspicious
McAfeeArtemis!CB72368FB134
MAXmalware (ai score=99)
VBA32TScope.Trojan.VB
PandaTrj/CI.A
YandexTrojan.GenAsa!O3bYNF95XJ4
IkarusTrojan.Win32.Refroso
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DUQR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Generic.22760067?

Trojan.Generic.22760067 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment