Trojan

Should I remove “Trojan.Generic.35320947”?

Malware Removal

The Trojan.Generic.35320947 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.35320947 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Generic.35320947?


File Info:

name: 0F7669CAB6E8AE61D671.mlw
path: /opt/CAPEv2/storage/binaries/728a4a29144ff1d92d0ed1f969465219849a433a807a9d314e9de7e9973b1cf8
crc32: E17AE3E0
md5: 0f7669cab6e8ae61d6713cad452495b5
sha1: d9ff334dd5041f8db5c801607f9772022c99c5bf
sha256: 728a4a29144ff1d92d0ed1f969465219849a433a807a9d314e9de7e9973b1cf8
sha512: b5eaea3196be1ff77a80e75cc17269e0cafc1a677ae5a100a9a5649a98936abbd1f1b44f1340f5101884789c4f4ba8487a74a066a59e037d97191d6027c7bde8
ssdeep: 98304:d4t2Xal2SGXYwQNmfcm481SA/VjkJ45DX0P3pHW0CXFDFWgB1dPMg:6t8alWiEd4J45EFW0C9VD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16626337A85AE59F1D01BCD364DFEEBC4BDB3382E0C58753EF58E466617621B098083A4
sha3_384: 3ecd9761fdaacf5c197294191576ed65750df490ab0b7d02bac23342ad6f4dee282fdac523fca659976e043397ed97ee
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-03-04 09:06:40

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Mail Address Book View Setup
FileVersion:
LegalCopyright:
ProductName: Mail Address Book View
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Generic.35320947 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.35320947
FireEyeTrojan.Generic.35320947
CAT-QuickHealTrojan.Ekstak
SkyhighArtemis
McAfeeArtemis!0F7669CAB6E8
MalwarebytesAdware.DownloadAssistant
SangforDropper.Win32.Agent.Vjmz
AlibabaTrojanDropper:Win32/Nekark.194a29ab
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0DC424
KasperskyTrojan.Win32.Ekstak.awfdp
BitDefenderTrojan.Generic.35320947
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Kqil
EmsisoftTrojan.Generic.35320947 (B)
F-SecureTrojan.TR/AD.Nekark.qjnjx
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
VaristW32/Trojan.SQBJ-3766
AviraTR/AD.Nekark.qjnjx
MAXmalware (ai score=81)
KingsoftWin32.Trojan.Ekstak.awfdp
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.awfdp
GDataWin32.Backdoor.Bodelph.CHX10R
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malware-gen.C5597277
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.236589782.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.Generic.35320947?

Trojan.Generic.35320947 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment