Trojan

Trojan.Generic.23052265 removal tips

Malware Removal

The Trojan.Generic.23052265 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23052265 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify system certificates

How to determine Trojan.Generic.23052265?


File Info:

crc32: A37FA3BF
md5: 1ce9be35d31134f4e1e07c1b8d9d418c
name: 1CE9BE35D31134F4E1E07C1B8D9D418C.mlw
sha1: b2f71c74d537590f1eeff18248d5417a241312b5
sha256: 15a12c4502fbb7dce57e55a762ba20b0e56751e9d75a3fa230131cdf10daa0f6
sha512: e3fb4318dc40539eb76edfc11dceb1d1607f0fefbd6a4dd5ac56a7b18e08520e5b045e4a3975c3ca88a65f38c369c895e3d36b6a46a52a6782108b28ac8b5748
ssdeep: 3072:GJO19nvlOm59sA5wgHB9R4bIncFDIPztR2C:GJotOWsA5dH14b+6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Baidu Inc.
InternalName: BDMiniDlUpdate.exe
FileVersion: 1.3.0.137
CompanyName: x767ex5ea6x5728x7ebfx7f51x7edcx6280x672fxff08x5317x4eacxff09x6709x9650x516cx53f8
PrivateBuild: 1.3.0.137
LegalTrademarks: Baidu
Comments: 2013-12-13T11:25:29.968000
ProductName: x767ex5ea6x8f6fx4ef6x4e2dx5fc3x52a9x624b
SpecialBuild: 0
ProductVersion: 1.3.0.137
FileDescription: x5347x7ea7x6a21x5757
OriginalFilename: BDMiniDlUpdate.exe
Translation: 0x0804 0x04b0

Trojan.Generic.23052265 also known as:

K7AntiVirusAdware ( 004bca541 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Inject1.55304
ALYacTrojan.Generic.23052265
CylanceUnsafe
ZillyaAdware.Agent.Win32.161165
SangforTrojan.Win32.Save.a
K7GWAdware ( 004bca541 )
Cybereasonmalicious.5d3113
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Baidu.B potentially unwanted
AvastFileRepMetagen [Malware]
BitDefenderTrojan.Generic.23052265
NANO-AntivirusTrojan.Win32.Inject1.dtmaas
MicroWorld-eScanTrojan.Generic.23052265
Ad-AwareTrojan.Generic.23052265
SophosGeneric PUA LC (PUA)
ComodoMalware@#2ceja1qoabcrm
VIPREUBar
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.1ce9be35d31134f4
EmsisoftTrojan.Generic.23052265 (B)
JiangminAdware.Agent.zma
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Generic.D15FBFE9
GDataTrojan.Generic.23052265
McAfeeArtemis!1CE9BE35D311
VBA32Trojan.Inject
YandexTrojan.GenAsa!963eUr/BFn0
FortinetRiskware/Baidu
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan.Generic.23052265?

Trojan.Generic.23052265 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment