Trojan

Trojan.Generic.22915102 removal guide

Malware Removal

The Trojan.Generic.22915102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22915102 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan.Generic.22915102?


File Info:

name: C248099FCDB437F16508.mlw
path: /opt/CAPEv2/storage/binaries/458de383a5bf952524818bf49a403fe133ddc40389661df7bb89185695f33182
crc32: E8D62D75
md5: c248099fcdb437f1650852c8b0ff4355
sha1: 4c1f048d5be6d28b0118bdbd87a711eb59b2d0ab
sha256: 458de383a5bf952524818bf49a403fe133ddc40389661df7bb89185695f33182
sha512: 9211d9da40954eb81ad01d6e6044db3a7aa05cb6f51b77a67764191b9de0defcf5f37f28f861401f17b1b014d053419e311b0e996b44b0da874662dc47bad28b
ssdeep: 384:FAfAn2NHavCSE60pGEUFi141GToYhn/5KL2LLzu6vt:DkHavCS70pGfi150cWCLzu6vt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164522B59A7DCCB71DABE06731C6362108770E6079902DB5F2CC921BA6F1738947927F8
sha3_384: 8f42847ae332ab85330070b4ed923b01ca29ddc82edfe53eb0002a8fa98049713c3ce52ea9337ca448bf533aa9c69d76
ep_bytes: ff2500204000546f4261736536345374
timestamp: 2018-04-23 18:05:35

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsFormsApplication4
FileVersion: 1.0.0.0
InternalName: seve.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: seve.exe
ProductName: WindowsFormsApplication4
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.Generic.22915102 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22915102
FireEyeGeneric.mg.c248099fcdb437f1
McAfeeGenericRXDM-SI!C248099FCDB4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforBackdoor.MSIL.Agent.zpm
BitDefenderTrojan.Generic.22915102
K7GWTrojan ( 0051ebe61 )
K7AntiVirusTrojan ( 0051ebe61 )
ESET-NOD32a variant of MSIL/Agent.BFE
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.Agent.zpm
AlibabaBackdoor:MSIL/Generic.30c09eef
NANO-AntivirusTrojan.Win32.Mlw.favutl
TencentWin32.Trojan.Generic.Svqu
Ad-AwareTrojan.Generic.22915102
EmsisoftTrojan.Generic.22915102 (B)
ComodoMalware@#iam2bfkn46w2
McAfee-GW-EditionGenericRXDM-SI!C248099FCDB4
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2696F8C
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.Generic.22915102
BitDefenderThetaGen:NN.ZemsilF.34294.am0@aK5Y6Xi
ALYacTrojan.Generic.22915102
MAXmalware (ai score=94)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
YandexTrojan.Agent!kvQqZbQpBvw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.BFE!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.22915102?

Trojan.Generic.22915102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment