Trojan

Trojan.Generic.4796786 removal tips

Malware Removal

The Trojan.Generic.4796786 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.4796786 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

220420101201.no-ip.biz

How to determine Trojan.Generic.4796786?


File Info:

crc32: 3F0D7A4F
md5: 3430fb4581496d25391422d1d5761ecc
name: 3430FB4581496D25391422D1D5761ECC.mlw
sha1: 702c5bf22265b1317081628adada2a4094c5acfc
sha256: b1f5b63358abec44727fee6b4853c47fc116072489ed64f494e9ca87f1456f81
sha512: 7cc15c009ec33b2dc8aba0601af6a813d81ae0a586f5c10a9959ce2fa0d42686c233b79205204786c6612b9c3c370b981702b5990e2542488f8f2a99cd961ed3
ssdeep: 6144:OG8JXLdb9dyguzVWym+7Ol4ZzRxA3kIF25smJewa5QlILvb:pUbdBdGW+iGZoyssaei
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Alexander Roshal 1993-2010
InternalName: WinRAR
FileVersion: 3.92.0
CompanyName: Alexander Roshal
ProductName: WinRAR
FileDescription: WinRAR archiver
OriginalFilename: WinRAR.exe
Translation: 0x0000 0x0000

Trojan.Generic.4796786 also known as:

K7AntiVirusTrojan ( 004d273c1 )
LionicTrojan.Win32.Fsysna.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Generic.4796786
CylanceUnsafe
ZillyaTrojan.Injector.Win32.637270
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Fsysna.98675aed
K7GWTrojan ( 004d273c1 )
Cybereasonmalicious.581496
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Injector.BPN.Gen
APEXMalicious
AvastWin32:GenMalicious-IOW [Trj]
ClamAVWin.Trojan.Autorun-13994
KasperskyTrojan.Win32.Fsysna.ddfx
BitDefenderTrojan.Generic.4796786
NANO-AntivirusTrojan.Win32.BPN.cylyyu
MicroWorld-eScanTrojan.Generic.4796786
TencentWin32.Trojan.Fsysna.Lhmu
Ad-AwareTrojan.Generic.4796786
SophosMal/Generic-S
ComodoMalware@#gt2owo4emiy3
BitDefenderThetaGen:NN.ZexaF.34236.vy1@a8iy57v
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.3430fb4581496d25
EmsisoftTrojan.Generic.4796786 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.4796786
Acronissuspicious
McAfeeArtemis!3430FB458149
MAXmalware (ai score=89)
PandaTrj/CI.A
RisingTrojan.Generic@ML.90 (RDML:blFNZfXDpnyWiICfYtMKMQ)
YandexTrojan.GenAsa!MKih10jFu7E
IkarusTrojan-Dropper.Win32.Vundo
AVGWin32:GenMalicious-IOW [Trj]
Paloaltogeneric.ml

How to remove Trojan.Generic.4796786?

Trojan.Generic.4796786 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment