Trojan

How to remove “Trojan.Generic.22868015”?

Malware Removal

The Trojan.Generic.22868015 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22868015 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.22868015?


File Info:

crc32: F57A5F47
md5: 07eaf5472cab6d104e57051b679554fe
name: 07EAF5472CAB6D104E57051B679554FE.mlw
sha1: a6bb6ccc7c200ae252260c2b952b3a4eafadb986
sha256: 6c8094a9572ad42a3798dc93b5a0511e08d8fd623130a6a855a53c9dfd37cea5
sha512: 1faa8d9d80086dc368f9932f61367b38342fd6424f85e6dda75fb1d8c291ff8da522fda4b19f43c982699a5bc57493a55aaa810763248bc576d8c09acd77b60e
ssdeep: 6144:AsX+VLMtZlYUHSJSHY48F0JIFgAmXAN+Lw8FmMM3NwGF5dezauC:AAlLLIHkANl8F9MdwIez3C
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xc2xa9. All rights reserved.
InternalName: Preceding Mstek
CompanyName: TeraByte Unlimited
FileDescription: Webrtc Early Saturation Writeall
LegalTrademarks: Copyright xc2xa9. All rights reserved.
Comments: Webrtc Early Saturation Writeall
ProductName: Preceding Mstek
ProductVersion: 6.1.55.8
PrivateBuild: 6.1.55.8
OriginalFilename: Preceding Mstek.exe
Translation: 0x0409 0x04b0

Trojan.Generic.22868015 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.Generic.22868015
CylanceUnsafe
ZillyaTrojan.Crusis.Win32.712
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Crysis.P
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crusis.btc
BitDefenderTrojan.Generic.22868015
NANO-AntivirusTrojan.Win32.Crusis.faptdk
MicroWorld-eScanTrojan.Generic.22868015
TencentWin32.Trojan.Crusis.Hze
Ad-AwareTrojan.Generic.22868015
SophosMal/Generic-S
ComodoMalware@#csdd0c8nfsfs
F-SecureTrojan.TR/Crusis.uidpf
BitDefenderThetaGen:NN.ZexaF.34684.smKfaqc!yAhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.07eaf5472cab6d10
EmsisoftTrojan.Generic.22868015 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crusis.uidpf
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Generic.D15CF02F
AegisLabTrojan.Win32.Crusis.j!c
ZoneAlarmTrojan-Ransom.Win32.Crusis.btc
GDataTrojan.Generic.22868015
Acronissuspicious
McAfeeArtemis!07EAF5472CAB
MAXmalware (ai score=81)
VBA32Trojan-Ransom.Crusis
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingRansom.Crusis!8.5724 (CLOUD)
YandexTrojan.Crusis!OkMNDUXKLjk
IkarusTrojan-Ransom.GandCrab
FortinetW32/Fareit.A
AVGWin32:Malware-gen

How to remove Trojan.Generic.22868015?

Trojan.Generic.22868015 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment