Trojan

What is “Trojan.Generic.6691243”?

Malware Removal

The Trojan.Generic.6691243 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.6691243 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Generic.6691243?


File Info:

name: F940ABD205EC2B4B4F5A.mlw
path: /opt/CAPEv2/storage/binaries/237aa1689ecf1be55ff4887c9bf8140070e9b70bfb487b62fcac83e4bcabc016
crc32: 47AEE37A
md5: f940abd205ec2b4b4f5ac6f32100029e
sha1: 0b6773c5d405facb193859da7aaab1a75ccbbbd4
sha256: 237aa1689ecf1be55ff4887c9bf8140070e9b70bfb487b62fcac83e4bcabc016
sha512: 2f78eec778bd77c5f71b22382a9fd5842798a52b55aee34629e5350a8eb8235143ab13561a2e95e79554afbb9b6d1fd824cf9b093ca40733fedd076f5e487bb8
ssdeep: 98304:kjXaRQxzSx0oEzVGb246brsrxCD8GLs0h4dn:kjIQ1O0oiVG/6/LD8I4B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B26337B156BC72DFE268630EB66B9F0ACD69D0CE9725247382EBD8776BDB100045C84
sha3_384: 1de67313e351b016a9d02f8ac1459edf80ef343376ecbb06a859ee0af2d20348085044c7a5b86f49ccbe814dddcc548d
ep_bytes: 60be00b05b018dbe0060e4fe5789e58d
timestamp: 2011-04-02 10:43:35

Version Info:

Translation: 0x0409 0x04b0
Comments: RFDROMSBGAT
CompanyName: JDWVCNBGOJXKYPNQ
FileDescription: CFTIZSQUPIXBKVWTILUHMKOYWZLF
LegalCopyright: udnl
LegalTrademarks: wgfhhbxnqzkk
ProductName: REEHAJDWVCNBGOJX
FileVersion: 14.16.0018
ProductVersion: 14.16.0018
InternalName: jcrjhe
OriginalFilename: jcrjhe.exe

Trojan.Generic.6691243 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.6691243
ClamAVWin.Adware.Archsms-9953324-0
FireEyeGeneric.mg.f940abd205ec2b4b
McAfeePWS-Zbot.gen.bas
CylanceUnsafe
ZillyaTrojan.ArchSMS.Win32.861
AlibabaRiskWare:Win32/ArchSMS.68a7a091
Cybereasonmalicious.205ec2
BaiduWin32.Trojan.Injector.fj
CyrenW32/S-29f4a955!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Injector.FOV
APEXMalicious
CynetMalicious (score: 99)
KasperskyHoax.Win32.ArchSMS.hjui
BitDefenderTrojan.Generic.6691243
NANO-AntivirusTrojan.Win32.ArchSMS.cvvdwb
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.6691243
SophosMal/Generic-R + Troj/VB-FOI
ComodoTrojWare.Win32.Refroso.rxu@4nu095
DrWebTrojan.SMSSend.458
VIPRETrojan.Generic.6691243
TrendMicroTROJ_GEN.R03BC0OIK22
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.6691243 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.6691243
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLHackTool[Hoax]/Win32.ArchSMS
ArcabitTrojan.Generic.D6619AB
ZoneAlarmHoax.Win32.ArchSMS.hjui
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
VBA32SScope.Hoax.ArchSMS.01486
ALYacTrojan.Generic.6691243
MalwarebytesMalware.AI.4210580901
TrendMicro-HouseCallTROJ_GEN.R03BC0OIK22
RisingTrojan.Multsarch!8.A28 (TFE:3:GkXPoa4t42E)
YandexTrojan.ArchSMS!BKF0kH8ktAI
Ikarusnot-a-virus:Hacktool.SMSHoax
FortinetRiskware/ArchSMS
BitDefenderThetaGen:NN.ZevbaF.34682.@pNfamGYT1hi
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Generic.6691243?

Trojan.Generic.6691243 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment