Trojan

Trojan.Generic.6188009 removal guide

Malware Removal

The Trojan.Generic.6188009 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.6188009 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Likely virus infection of existing system binary
  • Attempts to identify installed analysis tools by a known file location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Trojan.Generic.6188009?


File Info:

name: 8C2C15C2725512AB2857.mlw
path: /opt/CAPEv2/storage/binaries/4e863c40d5dcce501da3dc7c8ff116b2de489062b7b1d7c90285499a368841e0
crc32: F3C2327B
md5: 8c2c15c2725512ab285729d52fbd4c26
sha1: d3acb3e480bfe8b3a56c45cf3452edfde9d25349
sha256: 4e863c40d5dcce501da3dc7c8ff116b2de489062b7b1d7c90285499a368841e0
sha512: cfde99f0e8f2e55f0116340e944f5610cf4b640a8bcce3fb723ca8b565069c67bd86269f6bec94baf69d2d90e8902537ec145748fbc085eeda577a0340c2bdd5
ssdeep: 6144:3o/RTG1hT4U4ZG4HOK7NSCDxuOtAwc7VMocHx:5hUU4ZhHV74CDxtAwwvwx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A1412713BF10441E90387B4CFEA923BEC5BE3258AA4419D1F349386E962A75DAC548F
sha3_384: ee1ddb511f0e012b1f74494388551f76ccebf46f79927e63aaaf6abe2adc0909a34567974e61a42549dde0ee8e1740f8
ep_bytes: 60be002047008dbe00f0f8ff57eb0b90
timestamp: 2007-08-31 02:53:38

Version Info:

CompanyName: AVG Technologies CZ, s.r.o.
FileDescription: AVG Tray Monitor
FileVersion: 9.0.0.871
InternalName: avgtray
LegalCopyright: Copyright © 2010 AVG Technologies CZ, s.r.o.
OriginalFilename: avgtray.exe
ProductName: AVG Internet Security
ProductVersion: 9.0.0.871
PrivateBuild: Win32 Release_Unicode
SpecialBuild: Avg8VC8_2010_1109_133319(871), SVNRev 145063 (/branches/release/SmallUpdate9-12)
Translation: 0x0409 0x04e4

Trojan.Generic.6188009 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.6188009
FireEyeGeneric.mg.8c2c15c2725512ab
CAT-QuickHealWorm.SlenfBot.Gen
ALYacTrojan.Generic.6188009
CylanceUnsafe
ZillyaTrojan.Diple.Win32.1180
SangforExploit.Win32.ShellCode.gen
K7AntiVirusTrojan ( f1000f011 )
AlibabaExploit:Win32/ShellCode.4d14fe6f
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.272551
VirITTrojan.Win32.Generic.AXIS
CyrenW32/Risk.YREW-7251
SymantecW32.IRCBot.NG
ESET-NOD32a variant of Win32/Kryptik.LDY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1279
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.6188009
NANO-AntivirusTrojan.Win32.Meredrop.iesmj
SUPERAntiSpywareTrojan.Agent/Gen-FakeAVG
AvastWin32:Kryptik-AHL [Trj]
TencentWin32.Trojan.Generic.Eaxg
Ad-AwareTrojan.Generic.6188009
SophosMal/Generic-R + Mal/FakeAV-IU
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
DrWebTrojan.Packed.21467
VIPRETrojan.Win32.Kryptik.lbu (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftTrojan.Generic.6188009 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.6188009
JiangminTrojan.Generic.dxdvq
WebrootW32.Infostealer.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1861428
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.A.Diple.205960[UPX]
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Slenfbot.gen!D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FraudPack.R3415
McAfeeArtemis!8C2C15C27255
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.AI.1553884152
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingExploit.ShellCode!8.2A (CLOUD)
YandexTrojan.GenAsa!rTvAwvnOGnE
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.NAS!tr
BitDefenderThetaGen:NN.ZexaF.34212.mmKfaKg3Oebc
AVGWin32:Kryptik-AHL [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Generic.6188009?

Trojan.Generic.6188009 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment