Trojan

Trojan.Generic.35509412 (file analysis)

Malware Removal

The Trojan.Generic.35509412 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.35509412 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Generic.35509412?


File Info:

name: 0040A6842478ACE6DD99.mlw
path: /opt/CAPEv2/storage/binaries/5504f8a541afbd973ad0bfee31c9796ebe1f98c0ebd2927e456958d4ca17da22
crc32: B247EF69
md5: 0040a6842478ace6dd994cfad7d1ff06
sha1: 962b673b96da97deba92abd9c84f3f92eaa80f6e
sha256: 5504f8a541afbd973ad0bfee31c9796ebe1f98c0ebd2927e456958d4ca17da22
sha512: f29e80e1d9eca98b4302b39868ce93253e2af8df14ae99c8ed37a768f63cf52d207d4766c14b806b1e0bcbc14e47a08452990aac9479669c2d1fb8e1190ebadd
ssdeep: 98304:420fsKRwqB+9MMAmAlsijRjJ7LE1Yk2qgTxVtsShdugZ:4/uqWAmAlb/lqgT7tLugZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C263394EC9B87E8F943A1704570822609A8BBBF37A6265F071E256E075337349B7F31
sha3_384: 0ef7cb97317166386df48c346e6defb852245296e1a00612ffc98490952c246a2d32544f56cc4c9c9771ff9220a08b56
ep_bytes: 60be009041008dbe0080feff5789e58d
timestamp: 2012-12-31 00:38:51

Version Info:

FileDescription: 帮5淘购物助手
FileVersion: 5, 2, 3, 0
InternalName: B5TSetup
LegalCopyright: Copyright (C) 2013 B5MSoft
OriginalFilename: B5TSetup.exe
ProductName: 帮5淘购物助手
ProductVersion: 5, 2, 3, 0
Translation: 0x0804 0x04b0

Trojan.Generic.35509412 also known as:

LionicAdware.Win32.Generic.2!c
MicroWorld-eScanTrojan.Generic.35509412
FireEyeTrojan.Generic.35509412
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!0040A6842478
Cylanceunsafe
SangforPUP.Win32.Bang5mai.V9jm
K7AntiVirusAdware ( 004d9ee41 )
AlibabaAdWare:Win32/Generic.ead2bcf4
K7GWAdware ( 004d9ee41 )
VirITPUP.Win32.Generic.AG
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
CynetMalicious (score: 99)
BitDefenderTrojan.Generic.35509412
TencentWin32.Trojan.Agen.Vwhl
EmsisoftTrojan.Generic.35509412 (B)
F-SecureHeuristic.HEUR/AGEN.1313323
ZillyaAdware.Bang5mai.Win32.578
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Bang5mai
AviraHEUR/AGEN.1313323
Antiy-AVLGrayWare[AdWare]/Win32.Bang5mai
MicrosoftPUA:Win32/Bang5mai
ArcabitTrojan.Generic.D21DD4A4
GDataTrojan.Generic.35509412
VBA32BScope.Adware.Elex
MAXmalware (ai score=85)
MalwarebytesTrojan.ChinAd
RisingAdware.Bang5Mai!1.E0A2 (CLASSIC)
FortinetW32/Generic.AP.3541260
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Trojan.Generic.35509412?

Trojan.Generic.35509412 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment