Trojan

About “Trojan.Generic.6756628” infection

Malware Removal

The Trojan.Generic.6756628 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.6756628 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Kuwait)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine Trojan.Generic.6756628?


File Info:

name: 62CCD17C5F55CAFCC1A5.mlw
path: /opt/CAPEv2/storage/binaries/0bfd503f6c2c129ea44462db40365c7a00b9ca0eb502e8a3b68802853b52a4ce
crc32: C04FE3AC
md5: 62ccd17c5f55cafcc1a5e3268a11f113
sha1: b632c07af79f0ce72caff1ec7975be64eecf06e6
sha256: 0bfd503f6c2c129ea44462db40365c7a00b9ca0eb502e8a3b68802853b52a4ce
sha512: 2881b887165957d2692d9b48ce53561e7dad022f784fb8403731cda73283e652ded106ee852456f5251543cebb69084218b25c9624219a2d371fe74453f52ded
ssdeep: 12288:4/d0fwg82vSwcwOMyiiJZIdJhBi/pwG8XMvZNydCE2ROmtWN25KlGTe:UdjGPWtZIBfG8W6CEubglGy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103E401DF2644B908F6AEEFB7C89144C20745E8651873E58BBBC1E52152328BEB63705F
sha3_384: cb448bf953380ab0b64026f26897001a27a64e5491cc7f006b4d2b476974debde5cd69454065956861018de90c20cb98
ep_bytes: 60be009058008dbe0080e7ff5783cdff
timestamp: 2011-10-17 17:42:04

Version Info:

Translation: 0x0409 0x04b0
Comments: NikkoEmil Eastland Madsen Alistair Appian Knudson StromNepalNixon
ProductName: eqecrnlraftqddg
FileVersion: 1.02.0004
ProductVersion: 1.02.0004
InternalName: pasca
OriginalFilename: pasca.exe

Trojan.Generic.6756628 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Genome.4!c
MicroWorld-eScanTrojan.Generic.6756628
ALYacTrojan.Generic.6756628
CylanceUnsafe
VIPRETrojan.Generic.6756628
SangforTrojan.Win32.Injector.LFY
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaTrojan:Win32/Injector.2f450bc0
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.c5f55c
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Injector.LFY
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.6756628
NANO-AntivirusTrojan.Win32.Inject.hsxfh
AvastWin32:Trojan-gen
RisingDropper.Generic!8.35E (CLOUD)
Ad-AwareTrojan.Generic.6756628
EmsisoftTrojan.Generic.6756628 (B)
ComodoMalware@#1dc9cbm46rcu6
DrWebTrojan.Click2.6195
ZillyaTrojan.Genome.Win32.171686
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.62ccd17c5f55cafc
SophosMal/VBCheMan-C
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.6756628
JiangminTrojan/Genome.bhyl
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D671914
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!62CCD17C5F55
VBA32Trojan.Click
MalwarebytesMalware.Heuristic.1003
TencentWin32.Trojan.Generic.Adhl
YandexTrojan.Injector!P/rxfjKqJP0
IkarusTrojan.Win32.Genome
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dx.BBK4!tr
BitDefenderThetaGen:NN.ZevbaF.34784.PmLfauzT7BbG
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.6756628?

Trojan.Generic.6756628 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment