Trojan

Trojan.Generic.23060727 (file analysis)

Malware Removal

The Trojan.Generic.23060727 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23060727 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Generic.23060727?


File Info:

crc32: 9B046278
md5: ed3cf4f1f57223e9523170738fc8dbe4
name: ED3CF4F1F57223E9523170738FC8DBE4.mlw
sha1: 06dbf98d94962bc5fe4dba2e44d61a364c0b6a59
sha256: 1de4f05474040a4d01516356554d47168f79e688c02a58951eba61bfc0cb15dc
sha512: 48d4e7824de538c97b71939e7d998a0ad98bdb228c7bfed2977ec272f150e9d645432227f071605415c7d2917f023f6f5eb782db76ef01b2e0e0c7e29980edc6
ssdeep: 6144:1KXckLmdaY0yFTL4nLLuB4tiUGYxKMe8uCl3sn:2nryFTkuYxhxuCl3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: unregmp2.exe
FileVersion: 11.0.5721.5262 (WMP_11.090130-1421)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 11.0.5721.5262
FileDescription: Microsoft Windows Media Player x5b89x88c5x5b9ex7528x7a0bx5e8f
OriginalFilename: unregmp2.exe
Translation: 0x0804 0x04b0

Trojan.Generic.23060727 also known as:

LionicVirus.Win32.Virut.kYQV
Elasticmalicious (high confidence)
ALYacTrojan.Generic.23060727
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Virut.701f7c2a
Cybereasonmalicious.1f5722
CyrenW32/Virut.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Virtu-F [Inf]
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.23060727
MicroWorld-eScanTrojan.Generic.23060727
TencentWin32.Trojan.Symmi.Aliq
Ad-AwareTrojan.Generic.23060727
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virut.fm
FireEyeGeneric.mg.ed3cf4f1f57223e9
EmsisoftTrojan.Generic.23060727 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1115273
MicrosoftTrojan:Win32/Zpevdo.A
GDataTrojan.Generic.23060727
Acronissuspicious
McAfeeArtemis!ED3CF4F1F572
MAXmalware (ai score=100)
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:Virtu-F [Inf]
Paloaltogeneric.ml

How to remove Trojan.Generic.23060727?

Trojan.Generic.23060727 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment