Trojan

Should I remove “Trojan.Generic.34256997”?

Malware Removal

The Trojan.Generic.34256997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.34256997 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan.Generic.34256997?


File Info:

name: C764C8F1695F7ACC98BF.mlw
path: /opt/CAPEv2/storage/binaries/b5b479dd1d71c071622e9ffbfe4019f632f60d68dc0ad7a32dc8eb559493f584
crc32: 7C7B214D
md5: c764c8f1695f7acc98bfda95747e7141
sha1: d5a9eafac9d1cf382e5eae11a6ed9d51067bacd3
sha256: b5b479dd1d71c071622e9ffbfe4019f632f60d68dc0ad7a32dc8eb559493f584
sha512: d2c55b40552e4f493acb0433e6010742ff493c1078a5f55b27a951230972158a823c1d6fbe570bc00f4d57fb5a29a63dd6545a8a6c44c53b0683321a01e6e367
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4O3:fq6+ouCpk2mpcWJ0r+QNTBfzQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119936C05F3E242FAD9E2053200B6612F9776A6248724ADE7C34C3C839653ED59A7D3F9
sha3_384: 90d82b475b89b14f4dfcb730feb56825c43682a7d4f8b37ec1a9170fcd163700d00e9ac03d0e2e5e3af88df4e50aeaf6
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan.Generic.34256997 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tiny.trFe
MicroWorld-eScanTrojan.Generic.34256997
FireEyeGeneric.mg.c764c8f1695f7acc
SkyhighBehavesLike.Win32.RealProtect.nh
ALYacTrojan.Generic.34256997
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.Generic.34256997
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.ac9d1c
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
AlibabaTrojan:Win32/Niktol.4b1bd4d5
ViRobotTrojan.Win.Z.Agent.95106.B
RisingTrojan.Generic@AI.99 (RDML:xmJapJLUqP8d8+d7xHW6LA)
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.pmhod
VIPRETrojan.Generic.34256997
TrendMicroTROJ_GEN.R002C0DK323
EmsisoftTrojan.Generic.34256997 (B)
IkarusTrojan.Win32.Agent
WebrootW32.Trojan.Gen
VaristW32/Trojan.VFBA-8001
AviraTR/Redcap.pmhod
Antiy-AVLTrojan/Win32.Tiggre
ArcabitTrojan.Generic.D20AB865
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataTrojan.Generic.34256997
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5253524
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.85523
TrendMicro-HouseCallTROJ_GEN.R002C0DK323
TencentTrojan.BAT.Agentb.hb
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Generic.34256997?

Trojan.Generic.34256997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment