Trojan

Trojan.Generic.5962785 removal tips

Malware Removal

The Trojan.Generic.5962785 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.5962785 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Generic.5962785?


File Info:

name: 8A4AB265DBF50D2B6C58.mlw
path: /opt/CAPEv2/storage/binaries/2bb413e70ea171401537cb66a8dac99c3cebfac82385bdf78e05f941df93071b
crc32: B522433A
md5: 8a4ab265dbf50d2b6c58d95f756a1bc7
sha1: 895a9592ccd5355c55402c58b7e81eabff1cd621
sha256: 2bb413e70ea171401537cb66a8dac99c3cebfac82385bdf78e05f941df93071b
sha512: 742f27cc716ea8f93f292142eeb49da6c0451077b3e63ecacad0a5d7a1fb52074f9ef1b4fb9472617ecd4a57b2ef98a9b8462d66d34ecd027c69077ba2be115d
ssdeep: 3072:acasGolHcPSn+dFimUX1lY2AqfNGCz+fNEDHUhoWJlFYrpXc:RdpcKn+e1lB7NGvNEjUhbFep
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B70402085743C5ACE0A506B041C78B866D817F321D5BE1DEA985BB1FF9B7BC5E90E20E
sha3_384: 86217ff1c0f0897a89d3d6b361368183794a3f41a1e3530502c0ac004084340a37796a337487da649517e9bda20c142b
ep_bytes: 60be007041008dbe00a0feff57eb0b90
timestamp: 2005-02-27 19:37:16

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Trojan.Generic.5962785 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.SpyEyes.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.5962785
FireEyeGeneric.mg.8a4ab265dbf50d2b
CAT-QuickHealTrojanBNK.Zbot.mue
McAfeeArtemis!8A4AB265DBF5
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.37758
SangforTrojan.Win32.Zbot.TQ
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/SpyEyes.30e3ce08
K7GWTrojan ( 004af95c1 )
Cybereasonmalicious.5dbf50
BitDefenderThetaGen:NN.ZexaF.34212.lmKfa0To8Fdc
VirITTrojan.Win32.Panda.OX
CyrenW32/S-5f8a72a3!Eldorado
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.BHOZ
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
KasperskyTrojan-Spy.Win32.SpyEyes.eva
BitDefenderTrojan.Generic.5962785
NANO-AntivirusTrojan.Win32.SpyEyes.csxxsm
SUPERAntiSpywareTrojan.Agent/Gen-Morix
AvastFileRepMalware
TencentWin32.Trojan-spy.Spyeyes.Eaxe
Ad-AwareTrojan.Generic.5962785
EmsisoftTrojan.Generic.5962785 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebTrojan.PWS.Panda.387
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionPWS-Spyeye.fa
SophosML/PE-A + Mal/FakeAV-BW
APEXMalicious
GDataTrojan.Generic.5962785
JiangminTrojanSpy.SpyEyes.mej
eGambitGeneric.PSW
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.963943
KingsoftWin32.Troj.Generic.a.(kcloud)
ViRobotTrojan.Win32.A.SpyEyes.182272.F[UPX]
ZoneAlarmTrojan-Spy.Win32.SpyEyes.eva
MicrosoftPWS:Win32/Zbot.TQ
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R2551
VBA32Trojan.Zeus.EA.0999
ALYacTrojan.Generic.5962785
MAXmalware (ai score=95)
RisingSpyware.SpyEyes!8.4AA (CLOUD)
YandexTrojan.GenAsa!D7+Ca0RDHF8
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Generic.5962785?

Trojan.Generic.5962785 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment