Trojan

About “Trojan.Generic.22916459” infection

Malware Removal

The Trojan.Generic.22916459 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22916459 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

Related domains:

wpad.local-net

How to determine Trojan.Generic.22916459?


File Info:

name: E214451FA7468273EE35.mlw
path: /opt/CAPEv2/storage/binaries/99565fd2b2b5d08f2097360efb6caee688e0c0971531ca7afb0ea357da88e4d8
crc32: C0BE0C71
md5: e214451fa7468273ee353cdeff7a741b
sha1: b22745b9b19d405c982f8572b149f7d506bbb85a
sha256: 99565fd2b2b5d08f2097360efb6caee688e0c0971531ca7afb0ea357da88e4d8
sha512: 51b48972c67378a53a05f6c991511efeca22c411c6573629c9500341742bd295d3090bbea88f0342e1ed7bb4702a9f61eb4f52350281cc269f4167231f12d5d5
ssdeep: 12288:ivCo20H8NB4fGhagZ3UjwjHsTn9NWRQqulEnSjyLQFl4gzc/tRwL9I4kjMfQ+SR:iqz0cLjCMwlquoSjV4pSIRjuE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF256C27B2A18837C1621A38CC5B97EC5925FE902E389A473BF63F4C5EBD2407D1558B
sha3_384: 95b71affea918bddc6ca14f46bc513e68329d7bb6e73e51cd2a8f312b6c1475232acd98079eb262095cf17564199a802
ep_bytes: 558bec83c4f453b8709c4b00e8a7c4f4
timestamp: 2055-05-25 18:10:40

Version Info:

0: [No Data]

Trojan.Generic.22916459 also known as:

LionicTrojan.Win32.Virut.4!c
MicroWorld-eScanTrojan.Generic.22916459
FireEyeTrojan.Generic.22916459
CAT-QuickHealW32.Virut.D
McAfeeW32/Virut.rem.E
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
K7AntiVirusVirus ( 00001b761 )
AlibabaTrojan:Win32/WrongInf.38b36d64
K7GWVirus ( 00001b761 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Virut.AJ
SymantecTrojan.Gen.6
TrendMicro-HouseCallPE_VIRUT.GEN-2
Paloaltogeneric.ml
ClamAVWin.Trojan.Virut-129
BitDefenderTrojan.Generic.22916459
NANO-AntivirusVirus.Win32.Virut.pnbk
AvastWin32:Patched-IB [Trj]
Ad-AwareTrojan.Generic.22916459
EmsisoftTrojan.Generic.22916459 (B)
ComodoVirus.Win32.Virut.D@1h82v0
VIPREVirus.Win32.Virut.b (v)
TrendMicroPE_VIRUT.GEN-2
McAfee-GW-EditionW32/Virut.rem.E
SophosMal/Generic-S
IkarusVirus.Win32.Virut
GDataTrojan.Generic.22916459
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.Generic.22916459
MAXmalware (ai score=95)
APEXMalicious
AVGWin32:Patched-IB [Trj]
PandaGeneric Suspicious

How to remove Trojan.Generic.22916459?

Trojan.Generic.22916459 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment