Trojan

How to remove “Trojan.Generic.4629270”?

Malware Removal

The Trojan.Generic.4629270 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.4629270 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:43591, 0.0.0.0:43594, 0.0.0.0:43592, 0.0.0.0:43597, 0.0.0.0:43595
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Generic.4629270?


File Info:

crc32: D746A30A
md5: 20c2b984c1e9fb9877ac069c69bb670f
name: 20C2B984C1E9FB9877AC069C69BB670F.mlw
sha1: ccad0464de4ad771a1b96e1ee2d4e2bbb6cfbe08
sha256: fb1ac4942e298841866df409dbb64a9484c989eee7ef880ae938990bc19d305b
sha512: 1310794aaecd2ed8553837be11dae20031151732cb06a0c657261fcde12fc96af9fe4ce9336c8b81ee9fb7410451681010868b0eaa59fa3db70c77102dc119e3
ssdeep: 24576:3RZg1l9nCzgXa/QtRxcSBPeYFnTKbYrnQpnC/dO62jxw:3RqO0Xa4nxBPHlKCQpnCAtw
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Aleste Technology
InternalName: Agent Driver
FileVersion: 1.10.0.8
CompanyName: Aleste Technology
LegalTrademarks: Aleste Technology
Comments: Licensed to iVirtua Solutions
ProductName: Tz0
ProductVersion: 1.8.0
FileDescription: Agent Driver
OriginalFilename: wwtask.exe
Translation: 0x0409 0x04e4

Trojan.Generic.4629270 also known as:

DrWebTrojan.MulDrop16.11306
MicroWorld-eScanTrojan.Generic.4629270
FireEyeGeneric.mg.20c2b984c1e9fb98
CAT-QuickHealTrojan.Creprote
Qihoo-360HEUR/QVM17.0.93FB.Malware.Gen
ALYacTrojan.Generic.4629270
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Generic.4629270
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4c1e9f
BitDefenderThetaGen:NN.ZelphiF.34590.aj2fa034cgkG
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Banker-20078
KasperskyTrojan-Ransom.Win32.PornoAsset.cvhb
NANO-AntivirusTrojan.Win32.PornoAsset.fckyla
AvastFileRepMalware
RisingTrojan.Agent!8.B1E (RDMK:cmRtazp3N0evYPMZ74LFuojRk9AE)
Ad-AwareTrojan.Generic.4629270
EmsisoftTrojan.Generic.4629270 (B)
F-SecureHeuristic.HEUR/AGEN.1112442
ZillyaTrojan.Banker.Win32.30847
TrendMicroTrojanSpy.Win32.BANKER.CBBCDF
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosTz0 Remote Control (PUA)
IkarusTrojan-Banker.Win32.Banker
JiangminTrojan.Yoddos.bs
AviraHEUR/AGEN.1112442
MicrosoftPUA:Win32/Creprote
ArcabitTrojan.Generic.D46A316
GDataTrojan.Generic.4629270
CynetMalicious (score: 90)
McAfeeGenericRXAA-AA!20C2B984C1E9
MAXmalware (ai score=81)
VBA32Trojan-Ransom.PornoAsset
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTrojanSpy.Win32.BANKER.CBBCDF
TencentMalware.Win32.Gencirc.114ceea6
YandexTrojan.GenAsa!LVsrc4QLyis
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGFileRepMalware

How to remove Trojan.Generic.4629270?

Trojan.Generic.4629270 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment