Trojan

Trojan.Generic.32179372 malicious file

Malware Removal

The Trojan.Generic.32179372 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.32179372 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • The sample wrote data to the system hosts file.
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Generic.32179372?


File Info:

name: 6BED241531CD8E544B79.mlw
path: /opt/CAPEv2/storage/binaries/f1e9643fc51ffabf8db3e3172624a95e09a071f2e8a5c2c899e3a35267954594
crc32: EDEE807E
md5: 6bed241531cd8e544b79a1ad685c9f84
sha1: b5c5491b5b213f33622129070d75bf07f40a5da2
sha256: f1e9643fc51ffabf8db3e3172624a95e09a071f2e8a5c2c899e3a35267954594
sha512: 360c24ac5f9365f5b700d9a9334e8d155b0ac93e8a0e32ecf2325a2ad6257471265eb3735307549d0f67cadc1368f64219cfafe8d8562cbedf0800983cb456d6
ssdeep: 12288:HcELI7Yd7sK069FRpB3urq71j7stF+5HlHWGM442iCDMR5nWFpPoS2QZ+S:H27Ydsd69FnB3Gqu+5MZ4hiCD/bMQZ+S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D259E51BBC380F2D65515302CBB673BDA36BA460B25DFC75368ED686C332C1A53329A
sha3_384: ef2ded2e3ec54eebccfa720a9333c2be5575a6f8b2f5ec06de8bd2c9ee12feaa15233ca169cc0a93cda685ecb21ae91a
ep_bytes: 558bec6aff68c8364c00681008480064
timestamp: 2021-11-03 07:07:07

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Generic.32179372 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lpDo
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.32179372
McAfeeRDN/Generic.cf
MalwarebytesRamnit.Virus.FileInfector.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
AlibabaWorm:Win32/AutoRun.31868a1b
K7GWAdware ( 004b87ea1 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/Trojan.GRW.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
BitDefenderTrojan.Generic.32179372
EmsisoftApplication.Generic (A)
VIPRETrojan.Generic.32179372
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6bed241531cd8e54
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.137VCEU
JiangminTrojanDropper.Binder.boy
GoogleDetected
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Generic.D1EB04AC
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5109163
BitDefenderThetaGen:NN.ZexaF.36164.7q0@aq4ne3hb
ALYacTrojan.Generic.32179372
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CDT23
IkarusWorm.Win32.AutoRun
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
Cybereasonmalicious.b5b213
DeepInstinctMALICIOUS

How to remove Trojan.Generic.32179372?

Trojan.Generic.32179372 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment