Trojan

Trojan.Generic.34305591 (B) information

Malware Removal

The Trojan.Generic.34305591 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.34305591 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Deletes executed files from disk

How to determine Trojan.Generic.34305591 (B)?


File Info:

name: F5AADE7AAC20DB5BF20B.mlw
path: /opt/CAPEv2/storage/binaries/70d7c81225b5a88b380d40ed85fd36ecf9a1b930773a88248786e3a312f26848
crc32: 66141397
md5: f5aade7aac20db5bf20be11fb7e58bd8
sha1: bcb415e2fad97b385c4c82a44bc9148b414b3f69
sha256: 70d7c81225b5a88b380d40ed85fd36ecf9a1b930773a88248786e3a312f26848
sha512: cad421edd8ddd7e34e9890547cf51a8e80ade617da713f25b9356d5bb225040798e897d5fba9e7d4561d548af209434f2575309beb5ead75fade6a3121c9ff4f
ssdeep: 1536:j7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfSw77OC:/7DhdC6kzWypvaQ0FxyNTBfSE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D0A35A06B3E143BAD5E2003602B9513F8B72E52887506DE7C74C3C969613E999B7E3F6
sha3_384: b1c3ee51a87c0415956c75e87781839823bfc5afa46a30df924a11e42e5224035d08accd0ab63cf1f54117aec5e532c6
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan.Generic.34305591 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.X!c
MicroWorld-eScanTrojan.Generic.34305591
FireEyeGeneric.mg.f5aade7aac20db5b
CAT-QuickHealTrojan.GenericPMF.S15043657
SkyhighBehavesLike.Win32.RealProtect.ch
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.2fad97
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
AlibabaTrojan:Win32/Niktol.50d31a68
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.oxayp
EmsisoftTrojan.Generic.34305591 (B)
IkarusTrojan.BAT.Agent
AviraTR/Redcap.oxayp
Kingsoftmalware.kb.a.959
ArcabitTrojan.Generic.D20B7637
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5496484
DeepInstinctMALICIOUS
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
TencentTrojan.BAT.Agentb.ka
YandexTrojan.Agent!UpFcVi1xmYw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.EDI!tr
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Generic.34305591 (B)?

Trojan.Generic.34305591 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment