Trojan

Trojan.Generic.5259066 (file analysis)

Malware Removal

The Trojan.Generic.5259066 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.5259066 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Generic.5259066?


File Info:

name: D9A9FEC784C8C5D9E2F3.mlw
path: /opt/CAPEv2/storage/binaries/b03452a37655a1b4c77077365aa55b209f48f438cbab1bcd75861fd37a9eb217
crc32: 8B9F3ED6
md5: d9a9fec784c8c5d9e2f3cb0caac8da46
sha1: 4d9c0ab580c22c8695662fe769bf96fc11f7dea5
sha256: b03452a37655a1b4c77077365aa55b209f48f438cbab1bcd75861fd37a9eb217
sha512: dc3d3688e833c5a78167d566112fb5861414cacb8c3a2019ef8ce12f062d13bdc8344855dc240a0398f4bccbc6ecf86a22024e785c478d941f494b3f1686932d
ssdeep: 96:e+ag0d3ARcmIdmuWdAx9QWNwwE84T2DCkm/AnCe0OTa3q2WpcL0f1Vgi9iArHdo9:CgbIgbqxaRTiWM3a8fBxqZXsh7nte
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB328D40DBEC085EE9C1993613E75BF1935DB83D4490AE0DC1E6119FE8E0ABCD92EA12
sha3_384: 5bffdbab9c0a08e3db982b716c19c67d65de35194faa58fd4e666f8158eb4f24c97bd5a69188717daf8bb53620705c3d
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2009-06-16 15:31:18

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Lenovo (Beijing) Limited
ProductName: cpm
FileVersion: 1.00
ProductVersion: 1.00
InternalName: cpm
OriginalFilename: cpm.exe

Trojan.Generic.5259066 also known as:

LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.5259066
FireEyeGeneric.mg.d9a9fec784c8c5d9
ALYacTrojan.Generic.5259066
CylanceUnsafe
ZillyaTrojan.Pasta.Win32.6822
SangforTrojan.Win32.Generik.JJYRBKZ
BitDefenderTrojan.Generic.5259066
CrowdStrikewin/malicious_confidence_60% (W)
VirITTrojan.Win32.Generic.PVT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.JJYRBKZ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Pasta-286
KasperskyTrojan.Win32.Pasta.bal
AlibabaTrojan:Win32/Pasta.03f93c04
NANO-AntivirusTrojan.Win32.Dwn.edkjlw
ViRobotTrojan.Win32.A.Pasta.11264.B[UPX]
TencentWin32.Trojan.Pasta.Yolw
Ad-AwareTrojan.Generic.5259066
ComodoMalware@#r531svgbyvg3
DrWebTrojan.Siggen1.51273
VIPRETrojan.Generic.5259066
McAfee-GW-EditionBehavesLike.Win32.Trojan.lh
SophosMal/Generic-S
IkarusTrojan-Clicker.Win32.VB
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1EC
KingsoftWin32.Troj.Pasta.b.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.5259066
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R304918
McAfeeArtemis!D9A9FEC784C8
MAXmalware (ai score=99)
VBA32Trojan.Pasta
MalwarebytesMalware.Heuristic.1003
PandaTrj/StartPage.DAW
RisingTrojan.Agent!1.6719 (CLOUD)
YandexTrojan.Pasta!SDr+p4JA2gU
FortinetW32/Pasta.BAL!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.784c8c
AvastWin32:Trojan-gen

How to remove Trojan.Generic.5259066?

Trojan.Generic.5259066 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment