Trojan

Trojan.Generic.33561006 (file analysis)

Malware Removal

The Trojan.Generic.33561006 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.33561006 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Generic.33561006?


File Info:

name: 52172CAEBCA9D814A5F3.mlw
path: /opt/CAPEv2/storage/binaries/854cc8e2b6ec36e1cb9002af5594d33d3295fa7819f02f4a4502471ca503afe4
crc32: F7B9425D
md5: 52172caebca9d814a5f38837764f2bc6
sha1: b6c6147bfc8c634b77c161a4907203d6e76ea1de
sha256: 854cc8e2b6ec36e1cb9002af5594d33d3295fa7819f02f4a4502471ca503afe4
sha512: ea80b94de1599413996386af5614a1b703ad84c484db5be9f3448ca5cea1aad64caba37ce72c97ca0f633fe6d9fd1f93676725cca8615c6d069f283638117542
ssdeep: 6144:obHu6Ore6H68NOg3XOD4DVkasAQISzqJOZ:oMrh7fHOD48i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5D48C11B6008035E3A64731595AEAF509686E3927A9E4CFF3783E395E702D39B3724F
sha3_384: da717fa125a2c824daf6a8517f7a5aae1ea1f966ab09c251312e9d5b1b6e72e33eee5dbc2ee7489c24e722048889716e
ep_bytes: 1d61c13d2d66b69041dc760671db01bc
timestamp: 2013-09-14 01:04:08

Version Info:

0: [No Data]

Trojan.Generic.33561006 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Urelas.4!c
DrWebTrojan.Siggen6.36651
MicroWorld-eScanTrojan.Generic.33561006
ClamAVWin.Malware.Urelas-9645835-0
McAfeeGenericRXVV-WF!52172CAEBCA9
MalwarebytesCardSpy.Spyware.Stealer.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Urelas.3bca3bc5
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bfc8c6
BitDefenderThetaGen:NN.ZexaF.36196.OCZ@aGrdcJg
CyrenW32/Urelas.DN.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.33561006
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
EmsisoftTrojan.Generic.33561006 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Urelas.d
VIPRETrojan.Generic.33561006
TrendMicroTROJ_GEN.R03BC0DDO23
McAfee-GW-EditionBehavesLike.Win32.Generic.jz
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.52172caebca9d814
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.33561006
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Urelas
XcitiumTrojWare.Win32.Urelas.DAQ@5qwr5f
ArcabitTrojan.Generic.D20019AE
MicrosoftTrojan:Win32/Urelas.JU!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Urelas.R572293
ALYacTrojan.Generic.33561006
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0DDO23
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.33561006?

Trojan.Generic.33561006 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment