Trojan

Trojan.Generic.22785956 (file analysis)

Malware Removal

The Trojan.Generic.22785956 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22785956 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan.Generic.22785956?


File Info:

name: 476E802C4BD7BB6EC756.mlw
path: /opt/CAPEv2/storage/binaries/b951d29db3de2eee2bbc5844923f51ed3a7af403e76703d8a46e163671779b42
crc32: A1A6F362
md5: 476e802c4bd7bb6ec756666e5a5c3613
sha1: 99ad54cc30cf16efa4b9fd1a03d88638605e51d7
sha256: b951d29db3de2eee2bbc5844923f51ed3a7af403e76703d8a46e163671779b42
sha512: 17c091e53febf497bf7eb66f0b1b47956792001824ec71f7d76a4cc7a018239579b7be80a4ba57431ef9d26f3ed5c3f0d7cda4b5caf4f1b5791e7e2b6655802e
ssdeep: 1536:B3cpyORJLuB4P4AJJAwwJm9skrmVpqnroNQ51lp:B3c1fP4AJJAwwJm7rmV/N01l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F338C6926D048D7D9433B70297F9639F3BB5E2E3AB1434F9F147EA92F320C65610292
sha3_384: 2c1f53138ccd6f14c0e8ceacb8d24c24678587728e777b0992777f3db58cb6d95453f1c9c8094d0d8dd00d6365b6b766
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

FileDescription: Producer shd
FileVersion:
LegalCopyright: (C)
ProductName:
Translation: 0x0804 0x04e4

Trojan.Generic.22785956 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22785956
FireEyeTrojan.Generic.22785956
McAfeeRDN/Generic Dropper
CylanceUnsafe
K7AntiVirusTrojan ( 0050b64b1 )
AlibabaTrojanDropper:Win32/Generic.1954372f
K7GWTrojan ( 0050b64b1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TrendMicro-HouseCallTROJ_GEN.R002H09L321
Paloaltogeneric.ml
BitDefenderTrojan.Generic.22785956
AvastWin32:Evo-gen [Susp]
TencentWin32.Trojan.Generic.Pcta
Ad-AwareTrojan.Generic.22785956
SophosMal/Generic-S
ZillyaDropper.Agent.Win32.400843
McAfee-GW-EditionRDN/Generic Dropper
EmsisoftTrojan.Generic.22785956 (B)
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ViRobotTrojan.Win32.Z.Agent.52736.DXH
GDataTrojan.Generic.22785956
ALYacTrojan.Generic.22785956
TACHYONTrojan/W32.StartPage.52736.AA
MalwarebytesTrojan.ChinAd
APEXMalicious
IkarusTrojan-Dropper.NSIS.Agent
FortinetW32/Agent.BT!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.c4bd7b

How to remove Trojan.Generic.22785956?

Trojan.Generic.22785956 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment