Trojan

About “Trojan.Generic.32096892” infection

Malware Removal

The Trojan.Generic.32096892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.32096892 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Tofsee malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.32096892?


File Info:

name: B26E86BA5F8C86B2CA94.mlw
path: /opt/CAPEv2/storage/binaries/2e5f638cd55c5de0324fe222c1d60d916beadeb2fbc285292ef69b3ab4469946
crc32: 8561DCC6
md5: b26e86ba5f8c86b2ca9453faaf62e0c7
sha1: fc38b36772b8ddc671326f1ee660a4cf14698811
sha256: 2e5f638cd55c5de0324fe222c1d60d916beadeb2fbc285292ef69b3ab4469946
sha512: 9a060e7829ff64d980cd6be80660dd22fbe5cbd4216ffb55aaf8c72f7f905e248770e0cc6435b3f413b02838785ef408b20d1381b1b052bcb07ceddaf556f1b7
ssdeep: 3072:RVNbLpIL3Ad6Y/zRjvSJcngR4XF9JMPU7+bg7UoAxdsTR:LQL3Ad68ZS2gRAGPU7+bgQoAW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E04C0113A90C073C15669314868D2A56B3EFEB19D78968F77D83B2E5F711C23A3A347
sha3_384: 1054525ea7e7f28e45a0d79bf913df1a34c09b494eaa55c527b328deee2643efc5f056bd7547042758aa57d1f1938264
ep_bytes: e8d4540000e979feffff8bff558bec51
timestamp: 2022-01-17 04:30:01

Version Info:

Translations: 0x0543 0x007e

Trojan.Generic.32096892 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen19.5556
MicroWorld-eScanTrojan.Generic.32096892
FireEyeGeneric.mg.b26e86ba5f8c86b2
MalwarebytesTrojan.MalPack.GS
K7AntiVirusTrojan ( 0059ac471 )
Cybereasonmalicious.772b8d
SymantecPacked.Generic.528
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HRNP
TrendMicro-HouseCallTROJ_GEN.R014H0DKD22
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.32096892
TencentWin32.Backdoor.Tofsee.Vwhl
Ad-AwareTrojan.Generic.32096892
McAfee-GW-EditionBehavesLike.Win32.Lockbit.ch
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S + Troj/Krypt-QV
Antiy-AVLTrojan/Win32.Sabsik
KingsoftWin32.Troj.Generic.jm.(kcloud)
GridinsoftBackdoor.Win32.Tofsee.bot
ArcabitTrojan.Generic.D1E9C27C
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.gen
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R534351
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
MAXmalware (ai score=85)
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:9zyzOsaftGtQ1XqzDVJVHg)
SentinelOneStatic AI – Suspicious PE
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.32096892?

Trojan.Generic.32096892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment