Trojan

Trojan.Generic.471770 removal guide

Malware Removal

The Trojan.Generic.471770 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.471770 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools

Related domains:

wpad.local-net

How to determine Trojan.Generic.471770?


File Info:

name: 3E4147157B9D916260AC.mlw
path: /opt/CAPEv2/storage/binaries/62495b30a561d15f4336796164781b72efc14da34ecef45c25c2b2960ae99b4b
crc32: 73FC037A
md5: 3e4147157b9d916260ac5b12bbf34123
sha1: 76a855b10be98035a6682f61f33bbdb5c68dcb76
sha256: 62495b30a561d15f4336796164781b72efc14da34ecef45c25c2b2960ae99b4b
sha512: 4cb1cc95d219cb357f081154b2a847dd3f9c982c1ecd2a015352d39deffe5ab4ad37fa6430ee39ce6939b13be0f799f1248e49361636a4fe3cce6129dfbaac75
ssdeep: 384:HLkOVuITw9tcy55fIjSWDZMm5AuW7NoC5nxS9GvfwLkOVuITw9tNu7e:HLk9Ik9yy55f7qem5nC50lLk9Ik9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181A34BA7BBD084E1D1C859731BE70B32FD396870653382210B756D477E63AE1DB29435
sha3_384: 106aafb9c64556b7dab8ce23a80ffe47a831dec7376f5589230dd0ae3ea335066fbaed29e4ea74092502707f3dc19506
ep_bytes: 6a00e806080000a308404000e8f00700
timestamp: 2004-11-06 14:01:15

Version Info:

0: [No Data]

Trojan.Generic.471770 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.3e4147157b9d9162
McAfeeArtemis!3E4147157B9D
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaMalware:Win32/km_28ee70.None
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.RG potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.Generic.471770
MicroWorld-eScanTrojan.Generic.471770
AvastWin32:dUmPeX [Susp]
Ad-AwareTrojan.Generic.471770
SophosGeneric PUA HG (PUA)
McAfee-GW-EditionBehavesLike.Win32.Injector.cz
EmsisoftTrojan.Generic.471770 (B)
IkarusVirus.Win32.Horse
GDataTrojan.Generic.471770
JiangminTrojan.Generic.fses
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Suspicious/Win.dUmPeX.C4573245
Acronissuspicious
ALYacTrojan.Generic.471770
MAXmalware (ai score=83)
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R002H09KN21
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazo5UY+L7gnBqFQFu4uEkJLc)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/GameHack
AVGWin32:dUmPeX [Susp]
Cybereasonmalicious.57b9d9

How to remove Trojan.Generic.471770?

Trojan.Generic.471770 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment