Trojan

Trojan.Generic.22860541 removal instruction

Malware Removal

The Trojan.Generic.22860541 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22860541 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Installs itself for autorun at Windows startup
  • CAPE detected the VMProtectStub malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

iplogger.com

How to determine Trojan.Generic.22860541?


File Info:

name: 01D0880280CAF6554BFF.mlw
path: /opt/CAPEv2/storage/binaries/d72f683cfcced5384799e2194fc069c79f99f26f03d74c402d5a3e7bdc7f4e7b
crc32: E12034A5
md5: 01d0880280caf6554bff940bedabf9c1
sha1: 7f7f1441c05139a6c4ec0b21e2b0e5b15ea2b7da
sha256: d72f683cfcced5384799e2194fc069c79f99f26f03d74c402d5a3e7bdc7f4e7b
sha512: f8e317b17bb2dfc3d120b9f7cc665e0012662c6cfd0d690d5eb7a4703a1d51352e81c44476ddcc40484308e0de91eb91f835becb23eff9ebdd32cfa8457fea0a
ssdeep: 49152:SvOqcGLagCmP5Qy3IquBmqRB3fLUTlERdo5EveOM/Ww/pZ3:SjBBQyaXvLUH5EvrMPf3
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1FEC5D0D6B3DC0BE4E33F987A954BA706D972B8971738FA6E0D8016A50F23270251D772
sha3_384: 299ee0dab3e81051f460620fe792869838f7b53f767445ad4f88d6a21936c39c871c6957e509f8fc11c651cd46f2ca39
ep_bytes: 0f8b9024000068c5d190bee913edffff
timestamp: 2018-01-10 10:16:24

Version Info:

0: [No Data]

Trojan.Generic.22860541 also known as:

LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22860541
FireEyeGeneric.mg.01d0880280caf655
ALYacTrojan.Generic.22860541
MalwarebytesTrojan.MalPack.VMP.Generic
AlibabaRiskWare:Win32/VMProtect.c53fffd6
CrowdStrikewin/malicious_confidence_80% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.M
TrendMicro-HouseCallTROJ_GEN.R002C0WIO21
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Generic
BitDefenderTrojan.Generic.22860541
NANO-AntivirusRiskware.Win64.Mlw.exhvor
AvastWin64:Malware-gen
TencentWin32.Risk.Generic.Fhw
Ad-AwareTrojan.Generic.22860541
SophosGeneric PUA HP (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WIO21
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
EmsisoftTrojan.Generic.22860541 (B)
IkarusTrojan.Win64.Vmprotect
GDataTrojan.Generic.22860541
JiangminRiskTool.Agent.te
AviraHEUR/AGEN.1142549
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3PUP/Win64.Agent.C2364179
McAfeeArtemis!01D0880280CA
MAXmalware (ai score=94)
VBA32Trojan.Wacatac
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Generic.22860541?

Trojan.Generic.22860541 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment