Trojan

About “Trojan.Generic.22912859” infection

Malware Removal

The Trojan.Generic.22912859 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22912859 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • The sample wrote data to the system hosts file.

How to determine Trojan.Generic.22912859?


File Info:

crc32: E0AA79A1
md5: 904121a98be1c597139699b1dfd36b07
name: 904121A98BE1C597139699B1DFD36B07.mlw
sha1: f0d9a71c8c01714307e97372fc3a314edb0fc80e
sha256: 239c0c085e8d2cee8c32cc1f6ffcd1f94b4c2316864ac1f683207a1f9a5533a6
sha512: 8216c568eeec3b127ef0241c2862cf34df8fd3512ffb0e849762c0d6dc7b28683435cd41582c1dc0c934a00e990d28b9af8b200a1896187793c0ddb829d36ede
ssdeep: 12288:DH3I/asvudEBSNoFDv8D8GuwdiJv/SplIRcWXXaOUDLqOM3X5:bUBudEBAohKuwcnSpyoXs3X
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Generic.22912859 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Hosts.44212
CynetMalicious (score: 100)
ALYacTrojan.Generic.22912859
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/MBRlock.63214b01
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.98be1c
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.Generic.22912859
NANO-AntivirusTrojan.Win32.Hosts.fesopm
MicroWorld-eScanTrojan.Generic.22912859
Ad-AwareTrojan.Generic.22912859
SophosGeneric PUA PA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34294.FmGfaOHEvkjb
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.904121a98be1c597
EmsisoftTrojan.Generic.22912859 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.11B5R9D
McAfeeArtemis!904121A98BE1
MAXmalware (ai score=97)
VBA32BScope.Trojan.Hynamer
YandexTrojan.GenAsa!Ycbm/yOoXH0
IkarusTrojan.Win32.MBRlock
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Generic.22912859?

Trojan.Generic.22912859 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment