Trojan

Trojan.Generic.32198070 removal

Malware Removal

The Trojan.Generic.32198070 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.32198070 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Generic.32198070?


File Info:

name: B943D84ADA76D59852BA.mlw
path: /opt/CAPEv2/storage/binaries/d0f93d7deabdd7eb5e47cbd8559fae4989cf25d1f0aab078be6910ab207ba57d
crc32: 4A26B978
md5: b943d84ada76d59852ba461310f71ac5
sha1: 39e1cae94f698aedafb2228d51c52dcfcd85a0c9
sha256: d0f93d7deabdd7eb5e47cbd8559fae4989cf25d1f0aab078be6910ab207ba57d
sha512: 365bcc9f18f3d543402ffc7b22318af4e6a547b7562d4a5358e0ac4a8d2a997581b644d6e0bc9be500b9bc4ea19591a6de7f3a8f221ef8931b53d424e867e390
ssdeep: 49152:KiC91UiHcNTJyEqZnNDbPm+PPCmtzs88buSiM1lHvA:WJoTJ3aNDjm+Xr4uSiCPA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T106B5331466F3A061E82781B5B0425DF18B2FB4B799E42A198E7FC4D17DB93517B8C383
sha3_384: f2d9730b51d60752d39ff8ef3c17c6e4c3c53b644e23fa506b340cb4115d22279c7c9bd331b859ce6d039b42039aab2b
ep_bytes: 807c2408010f85e401000060be000089
timestamp: 2022-03-02 00:55:08

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Generic.32198070 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lt2b
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.32198070
FireEyeGeneric.mg.b943d84ada76d598
SkyhighBehavesLike.Win32.Generic.vc
ALYacTrojan.Generic.32198070
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_60% (W)
ArcabitTrojan.Generic.D1EB4DB6
BitDefenderThetaGen:NN.ZedlaF.36744.uoSfaqTGzRbb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
BitDefenderTrojan.Generic.32198070
NANO-AntivirusTrojan.Win32.PUPStudio.jrshik
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.Generic.32198070 (B)
VIPRETrojan.Generic.32198070
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
VaristW32/Trojan.GRW.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
ViRobotAdware.Tiggre.2430464
GDataWin32.Trojan.PSE.1KQMTX4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.R606706
McAfeeArtemis!B943D84ADA76
MAXmalware (ai score=87)
VBA32BScope.Trojan.Tiggre
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H09L823
IkarusTrojan.Win32.Krypt
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Generic.32198070?

Trojan.Generic.32198070 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment