Trojan

Trojan.Generic.23159341 malicious file

Malware Removal

The Trojan.Generic.23159341 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23159341 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan.Generic.23159341?


File Info:

name: 5943E7E62B915151E242.mlw
path: /opt/CAPEv2/storage/binaries/c1d58b3d1c919f18d0562989426594aa3672d738583c32a7387ebd633e584e03
crc32: 11F7D772
md5: 5943e7e62b915151e242f00c33cb4eda
sha1: ed65530ccf67d49f33dd8a54b748a8427efaee4d
sha256: c1d58b3d1c919f18d0562989426594aa3672d738583c32a7387ebd633e584e03
sha512: ae9faabd593c77a91160bc7b46b0d20a5393802e66abdf453c9efb6856df9ea93a418eda8464cbf78c250926bbb0038695f7a7736ada72e46df50c49fd0a5390
ssdeep: 24576:k4GHnhIzOaG+t+EXXy1SgikOt8XFt4k2FJLwP:zshdaG+t+EXXy51u7FJLw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4052324E0EE6227D5D1167980F309FC3628F952F9741A83E391FA59BE362099F1379C
sha3_384: a8779898e7d61660ec9cea2f1ce9f40bb00eaa562a2d8f6dd2ba51fa9f74a56621851b97f63e4c2c70ed5e38eda6aad3
ep_bytes: 60be00704f008dbe00a0f0ff57eb0b90
timestamp: 2018-10-09 18:10:19

Version Info:

FileVersion: 0.9.0.0
Comments: Pomocnik TSO - program do pomocy podczas gry w TSO posiada brakujące funkcje nie występujące w grze. Pomocnik nie zastępuje gracza jest tylko pomocą.
FileDescription: Pomocnik w grze TSO
ProductVersion: 0.9
LegalCopyright: Unnamed
ProductName: Pomocnik TSO
Publisher: xxx
Translation: 0x0415 0x04b0

Trojan.Generic.23159341 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Banload.4!c
MicroWorld-eScanTrojan.Generic.23159341
FireEyeTrojan.Generic.23159341
McAfeeArtemis!5943E7E62B91
CylanceUnsafe
ZillyaDownloader.Banload.Win32.87060
AlibabaTrojanDownloader:Win32/Banload.623644fa
Cybereasonmalicious.62b915
CyrenW32/FakeDoc.J.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.MEJNRUB
TrendMicro-HouseCallTROJ_GEN.R002C0GH221
KasperskyTrojan-Downloader.Win32.Banload.abgcv
BitDefenderTrojan.Generic.23159341
NANO-AntivirusTrojan.Win32.Banload.ixbzpa
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Banload.Svrf
Ad-AwareTrojan.Generic.23159341
ComodoMalware@#it5mweqb5gxq
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GH221
McAfee-GW-EditionBehavesLike.Win32.DLSponsor.cc
EmsisoftTrojan.Generic.23159341 (B)
IkarusTrojan-Downloader.Banload
GDataTrojan.Generic.23159341
AviraTR/Dldr.Banload.qybvh
Antiy-AVLTrojan/Generic.ASCommon.16F
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 99)
VBA32TrojanDownloader.Banload
ALYacTrojan.Generic.23159341
APEXMalicious
FortinetW32/Banload.ABGCV!tr.dldr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Generic.23159341?

Trojan.Generic.23159341 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment