Trojan

Should I remove “Trojan.Generic.4868742”?

Malware Removal

The Trojan.Generic.4868742 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.4868742 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Generic.4868742?


File Info:

name: 6B0A8FF930371630341E.mlw
path: /opt/CAPEv2/storage/binaries/7bf189c5a6680ab913cbe9a7936403e444d5a90b65ce80fe33c54682bb57fe36
crc32: 92AC0A6C
md5: 6b0a8ff930371630341eeb771f9447d1
sha1: 0d7c7f4be4ad0248682dbbe0a7845c7e3ae4289a
sha256: 7bf189c5a6680ab913cbe9a7936403e444d5a90b65ce80fe33c54682bb57fe36
sha512: 5b0cffb4ca7a9e67df04b01a54dbf3d8a20cd613ab25591bbdee88cdad446cf32cdb02a2d1b7812e29a92fd986a4d2572456d6dde9be8466bd0d691be649f508
ssdeep: 3072:ynkuHrys263IrWnWBfu2IDJnNsa9MGMH8F64mvIXKoAlvOS5i:ynxLys1znqubUa9MGDckIvu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B94F12BA693C5FBC1F90371499B2B3CE7BF53C142010325524DE93E7A93A5E7916E60
sha3_384: 81d934001ba976357f99d52ee23fc8422df51010bcf3a14c0eed640739297884de2abf904b7d18ecbb09a14421b59841
ep_bytes: 8d55e052ff75e05051ff75fc518d4de8
timestamp: 2008-06-01 22:36:01

Version Info:

0: [No Data]

Trojan.Generic.4868742 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.387
CynetMalicious (score: 100)
FireEyeGeneric.mg.6b0a8ff930371630
ALYacTrojan.Generic.4868742
CylanceUnsafe
VIPREPacked.Win32.Zbot.gen.y.7 (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/DUmPeX.05d21ae6
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.930371
BitDefenderThetaGen:NN.ZexaF.34212.zmW@aeLrr7oc
VirITTrojan.Win32.Generic.WDK
CyrenW32/Zbot.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.ZR
TrendMicro-HouseCallTSPY_ZBOT.WKD
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.apmm
BitDefenderTrojan.Generic.4868742
NANO-AntivirusTrojan.Win32.Zbot.bhscr
MicroWorld-eScanTrojan.Generic.4868742
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11bbdf7a
Ad-AwareTrojan.Generic.4868742
EmsisoftTrojan.Generic.4868742 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Zbot.Win32.80318
TrendMicroTSPY_ZBOT.WKD
McAfee-GW-EditionBehavesLike.Win32.Picsys.gz
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Wemon
GDataTrojan.Generic.4868742
JiangminTrojanSpy.Zbot.anmr
eGambitGeneric.Trojan
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Generic.D4A4A86
ZoneAlarmTrojan-Spy.Win32.Zbot.apmm
MicrosoftPWS:Win32/Zbot.gen!Y
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.Zbot.R2049
Acronissuspicious
McAfeeArtemis!6B0A8FF93037
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!/rzez7Yo6d4
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.1747117.susgen
FortinetW32/Zbot.U!tr
WebrootW32.Infostealer.Zeus
AVGWin32:Trojan-gen
PandaTrj/Sinowal.XGN
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Generic.4868742?

Trojan.Generic.4868742 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment