Trojan

What is “Trojan.Generic.34223174”?

Malware Removal

The Trojan.Generic.34223174 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.34223174 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Generic.34223174?


File Info:

name: 1A165288D7C5D2CF2D58.mlw
path: /opt/CAPEv2/storage/binaries/66acd13df592c93c7448d1b4460a7270104cf6836edcbdec11e3719c578016a1
crc32: C4965200
md5: 1a165288d7c5d2cf2d587ef393d8cf44
sha1: cd86962edfd6d4be60558c9b350f581913e452ed
sha256: 66acd13df592c93c7448d1b4460a7270104cf6836edcbdec11e3719c578016a1
sha512: 5d7257268365b5fc87b01edf17361791f2839bd08b962c3f6b062db4b589920bd439cef404a10e18cafb411417616f895d7d32bf6303129d6c49acf694931916
ssdeep: 24576:jApUJimMVGNRd2Moy3SWfWCKBfnUF4hywPOjxErZB6RB2OlwsU:EpQyybU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D375E973D1108851E03906B1A2B2073C3A74EBB658749B57DFD4BDF4AE79A328F9261C
sha3_384: 13723502e982803272bdbe6ed64a1172c28d37e6ed108fdfa4d64703ff1b9da75fbeb72147c38d23d57e6fe44a10fd4f
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 2.981.2012.715
FileDescription: 挡屏提醒休息,http://ruanjianfabu.blog.163.com
ProductName: 挡屏提醒休息,http://ruanjianfabu.blog.163.com
ProductVersion: 2.981.2012.715
CompanyName: 1790042182@qq.com,http://ruanjianfabu.blog.163.com
LegalCopyright: 1790042182@qq.com,http://ruanjianfabu.blog.163.com
Comments: 挡屏提醒休息,http://ruanjianfabu.blog.163.com
Translation: 0x0804 0x04b0

Trojan.Generic.34223174 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.34223174
FireEyeGeneric.mg.1a165288d7c5d2cf
SkyhighBehavesLike.Win32.Generic.th
ALYacTrojan.Generic.34223174
Cylanceunsafe
VIPRETrojan.Generic.34223174
SangforTrojan.Win32.FlyStudio.Vo7s
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Generic.34223174
K7GWTrojan ( 005194cc1 )
K7AntiVirusTrojan ( 005194cc1 )
VirITTrojan.Win32.Click2.DFZZ
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
SophosGeneric Reputation PUA (PUA)
DrWebTrojan.Click3.31357
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.34223174 (B)
Webroot
VaristW32/FlyAgent.J.gen!Eldorado
MAXmalware (ai score=88)
Kingsoftmalware.kb.a.990
MicrosoftTrojan:Win32/Wacatac.A!ml
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
ArcabitTrojan.Generic.D20A3446
SUPERAntiSpywareTrojan.Agent/Gen-Faker
GDataWin32.Riskware.FlyStudio.C
CynetMalicious (score: 100)
McAfeeArtemis!1A165288D7C5
DeepInstinctMALICIOUS
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H09JJ23
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.edfd6d
AvastWin32:TrojanX-gen [Trj]

How to remove Trojan.Generic.34223174?

Trojan.Generic.34223174 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment