Trojan

Trojan.Generic.4079682 removal tips

Malware Removal

The Trojan.Generic.4079682 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.4079682 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Generic.4079682?


File Info:

name: 9CC5EDE08F8621D6EC33.mlw
path: /opt/CAPEv2/storage/binaries/19349487975f704d057f4d5e6b1968e442e67a84f38b080f2038fa8272e986a1
crc32: 357C38C2
md5: 9cc5ede08f8621d6ec3345db5a1a5ed1
sha1: bb2130153bdb8f925b15caa9ac36b34c020bdf87
sha256: 19349487975f704d057f4d5e6b1968e442e67a84f38b080f2038fa8272e986a1
sha512: 734b0bb77a2986b6d1e931334deb5193ba1832668b974e0aa1a4d3dd5b4c0ba09bbada842e80f22d3c8e5ce027bf9fbff70bc5da8bd1f2b4cb2a49a175703e74
ssdeep: 12288:0t1ix2MaJPp/cw8d+xzaw7O6Pgq+aGShET:s0wJPpUX+xzvJP9+ahhE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124C46D66F6E09437D2765E3CCC1FD7A89829BE502D39A84A3BF41D4C8F387417929293
sha3_384: ea074a8aa6329ffa6e35b3a5151a6f3f37ff79eebba1fed6a38890551c0c00ea3a6e8a5390c2643732afd6eec58521b1
ep_bytes: 558bec83c4f0535657b898114700e8f5
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Generic.4079682 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.StartPage.ldeu
MicroWorld-eScanTrojan.Generic.4079682
ClamAVWin.Trojan.Startpage-2437
FireEyeGeneric.mg.9cc5ede08f8621d6
McAfeeGeneric StartPage.ag
MalwarebytesBHO.Trojan.Clicker.DDS
VIPRETrojan.Generic.4079682
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2e2987b.None
K7GWTrojan ( 004d08ee1 )
K7AntiVirusTrojan ( 004d08ee1 )
BaiduWin32.Trojan.StartPage.af
CyrenW32/StartPage.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/StartPage.NRP
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.StartPage.aboz
BitDefenderTrojan.Generic.4079682
NANO-AntivirusTrojan.Win32.StartPage.btani
SUPERAntiSpywareTrojan.Agent/Gen-StartPage
AvastWin32:StartPage-AHS [Trj]
TencentMalware.Win32.Gencirc.10bddd42
SophosMal/Generic-R
F-SecureAdware:W32/BHO.EZF
DrWebBackDoor.BlackHole.4474
ZillyaTrojan.StartPage.Win32.7494
TrendMicroTROJ_STARTP.SMHB
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan.Generic.4079682 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.StartPage.D
JiangminTrojan/StartPage.ewt
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.StartPage
XcitiumTrojWare.Win32.Startpage.~NRP@1rmysw
ArcabitTrojan.Generic.D3E4042
ViRobotTrojan.Win.Z.Startpage.544456
ZoneAlarmTrojan.Win32.StartPage.aboz
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.StartPage.R1191
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.36318.HGX@aOHNHzmb
ALYacTrojan.Generic.4079682
MAXmalware (ai score=87)
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/StartPage.DID
TrendMicro-HouseCallTROJ_STARTP.SMHB
RisingBackdoor.Agent!1.69C2 (CLASSIC)
YandexTrojan.Startpage.Gen.11
IkarusTrojan.Win32.StartPage
MaxSecureTrojan.Malware.1703705.susgen
FortinetW32/StartPage.AA!tr
AVGWin32:StartPage-AHS [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Generic.4079682?

Trojan.Generic.4079682 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment