Trojan

Trojan.Generic.32048168 removal tips

Malware Removal

The Trojan.Generic.32048168 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.32048168 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Trojan.Generic.32048168?


File Info:

name: A8F334C37ED01B61F6F5.mlw
path: /opt/CAPEv2/storage/binaries/974e524183b9f52503617e3eac23005adccd7c811a60497bc9c9049ade1eef6d
crc32: C161FA52
md5: a8f334c37ed01b61f6f52b4a8d5d5a9d
sha1: 57a81a66e391a3554f146bc90dabf8f7031c4f3d
sha256: 974e524183b9f52503617e3eac23005adccd7c811a60497bc9c9049ade1eef6d
sha512: 482b62bf067cbacd8a798ca7982a460072a2eeef66dc2ca0311badacfb44edf15e4e97c418274930d1f3259d5192f06248b7a90032327fc4548b513e61a75177
ssdeep: 49152:bjOQb4CZoj8+u8yWKEgIt0y6e3RPz6+s8KuqGaX0ToIBAUZLYBBD:Gzu8yWKEgFPiLJBAUZLat
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140F5C002F642C1F2F5164130087AA73AD935DE661F618AC3B7A4FE6D6D332A1963734E
sha3_384: dee4ba576b5b5cd824df66afb49d7bba243c352b698e6128e0d3461ae9e851435bc8e12fce5b3289a844dc84a4e92302
ep_bytes: 558bec6aff68a8d46a006894a0500064
timestamp: 2022-11-02 11:33:06

Version Info:

FileVersion: 1.0.0.0
FileDescription: Moing
ProductName: Moing
ProductVersion: 1.0.0.0
CompanyName: Moing
LegalCopyright: Moing
Comments: Moing
Translation: 0x0804 0x04b0

Trojan.Generic.32048168 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lwTm
tehtrisGeneric.Malware
DrWebTrojan.Siggen8.14688
MicroWorld-eScanTrojan.Generic.32048168
FireEyeGeneric.mg.a8f334c37ed01b61
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.6e391a
BitDefenderThetaGen:NN.ZexaF.34754.pt0@aeuPTMbH
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
BitDefenderTrojan.Generic.32048168
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
Trapminesuspicious.low.ml.score
IkarusTrojan.Agent
GDataWin32.Trojan.PSE.161DS2T
GoogleDetected
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.C5269821
McAfeeArtemis!A8F334C37ED0
MAXmalware (ai score=86)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
SentinelOneStatic AI – Suspicious PE
FortinetW32/CoinMiner.65CA!tr

How to remove Trojan.Generic.32048168?

Trojan.Generic.32048168 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment