Trojan

Trojan.Generic.32420559 (file analysis)

Malware Removal

The Trojan.Generic.32420559 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.32420559 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Generic.32420559?


File Info:

name: 9B4294035F11107D0FBF.mlw
path: /opt/CAPEv2/storage/binaries/baf7a600f9e40ca321247d31d9825149da744c5dcc4535d7ccc72d505beea180
crc32: 81AFE138
md5: 9b4294035f11107d0fbfb66dd12be24e
sha1: 905005f347f7e4606adf0d6f4ef2ff89d40590d5
sha256: baf7a600f9e40ca321247d31d9825149da744c5dcc4535d7ccc72d505beea180
sha512: 7fbb5e1f13ef167a0ceba2fe0b74c9c69576d936406527ecd267055401195ec057fb25b00ed3ad89afeb5951fb63d86a89e540ddbfca803be43089f11866a4b7
ssdeep: 12288:R476u8ZAMAUaqnZFa8AhY9ET8uu0fp8mjnq0WKKYc24C1KXnNR5nWFpPoSH4:R476xZ8UaqnZFDAm9s8uu0B8fRC/bl4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD25B062B68280F3D615597004B76737DA74A60B2F25CFCBD3A4DE385C32191B63B2B9
sha3_384: b121dd976fb3f235a80d664acd3f2523e582e358fc85960ba32caf0026399843294523e0d0ff8c08a1987169020ce88e
ep_bytes: 558bec6aff68b8cf4c0068648a480064
timestamp: 2021-09-24 18:50:20

Version Info:

FileVersion: 1.0.1.0
FileDescription: 夜风论坛专用直链解析工具
ProductName: 夜风论坛专用直链解析工具
ProductVersion: 1.0.1.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 夜风论坛专用直链解析工具
Translation: 0x0804 0x04b0

Trojan.Generic.32420559 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.32420559
FireEyeGeneric.mg.9b4294035f11107d
ALYacTrojan.Generic.32420559
MalwarebytesTrojan.MalPack.FlyStudio
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWAdware ( 004b87ea1 )
K7AntiVirusTrojan ( 005246d51 )
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Generic-9820446-0
BitDefenderTrojan.Generic.32420559
TACHYONTrojan/W32.Agent.1007616.GT
EmsisoftTrojan.Generic.32420559 (B)
VIPRETrojan.Generic.32420559
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1THOGOA
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Generic.D1EEB2CF
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5079987
McAfeeRDN/Generic.rp
MAXmalware (ai score=89)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CEI23
IkarusPUA.BlackMoon
FortinetW32/CoinMiner.PHP!tr
BitDefenderThetaGen:NN.ZexaF.36250.9q0@aCqeVKkb
Cybereasonmalicious.347f7e
DeepInstinctMALICIOUS

How to remove Trojan.Generic.32420559?

Trojan.Generic.32420559 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment