Trojan

Trojan.Generic.23062413 (file analysis)

Malware Removal

The Trojan.Generic.23062413 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23062413 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

rl.ammyy.com

How to determine Trojan.Generic.23062413?


File Info:

crc32: 59311E40
md5: 810d5c7fefa5edeb8c8f4c946b8e7c95
name: 810D5C7FEFA5EDEB8C8F4C946B8E7C95.mlw
sha1: 2fad4078af40068e4d25daeb27cbbc7f00775a2c
sha256: 11cebeae511111b26cc6c60214edf410a02e9e152ac188e2be4bbafd1d8e93d3
sha512: 82423665f2ff57a461975df082cad510baa9614b989757c2bc3206993655966c502452e6da356f2d662a61fb3223d1d2d70b84a26d777778edd2a7d148edbeaa
ssdeep: 12288:vlSQ9Ze1m9UGFUUh/H+7j3uqlO/xreVxDbxjm9t6lTd/bPg/vP:gQ9o1zG3+n3uql4eHI90lTd/Mv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Generic.23062413 also known as:

K7AntiVirusUnwanted-Program ( 004d38111 )
LionicTrojan.Win32.Blocker.j!c
ALYacTrojan.Generic.23062413
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.40133
SangforRansom.Win32.Blocker.ldqq
AlibabaRansom:Win32/Blocker.ef689930
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.fefa5e
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.ldqq
BitDefenderTrojan.Generic.23062413
NANO-AntivirusTrojan.Win32.Blocker.iwsyvp
MicroWorld-eScanTrojan.Generic.23062413
TencentWin32.Trojan.Blocker.Dvzh
Ad-AwareTrojan.Generic.23062413
SophosMal/Generic-S
ComodoMalware@#3g1k84unj1xjf
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.810d5c7fefa5edeb
EmsisoftTrojan.Generic.23062413 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftProgram:Win32/Wacapew.C!ml
GDataTrojan.Generic.23062413
TACHYONRansom/W32.Blocker.582916
AhnLab-V3Malware/Win32.Generic.C2686551
McAfeeArtemis!810D5C7FEFA5
MAXmalware (ai score=80)
PandaTrj/CI.A
YandexTrojan.Blocker!oBBuenn+v1E
FortinetW32/Blocker.B!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASTIA

How to remove Trojan.Generic.23062413?

Trojan.Generic.23062413 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment