Trojan

Should I remove “Trojan.Generic.6839997”?

Malware Removal

The Trojan.Generic.6839997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.6839997 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Generic.6839997?


File Info:

name: B4E2E2D053B377BCA3EF.mlw
path: /opt/CAPEv2/storage/binaries/1b08ae544957332a8785a6d49e567f5cd271453cd932ccf774f9bea3adb637a8
crc32: C369D905
md5: b4e2e2d053b377bca3efb1ac277a4ae8
sha1: 8107b6e2cd704aa7f196dd9b413986a2a2ff9a75
sha256: 1b08ae544957332a8785a6d49e567f5cd271453cd932ccf774f9bea3adb637a8
sha512: acaf17c1ca7aec7c37cfff3aa5fd9c3fcc35b978bf340511a98c24a2a6cdd617a504f5fb9a80525ecc094263b2ac0b615ff216059324d9017cdcacad8d38c4ca
ssdeep: 768:ddoyt56iOWdJppPWcagYHJfBSWnfBSWnfBSWnfBSWnfBSWH:J6eppPbapZSWnZSWnZSWnZSWnZSWH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159B40950FF454D44E6F10A330A79FE6153B29DAA8436170B0F5C3E6D3FBA3A14DAA942
sha3_384: 0d44edfe81d7af6cd7bb1e28cb09288b68d4c35fcb9ed096a0ffdcc51fb38bdb7c82a5c1cbe36990b6512ec5e9ff702b
ep_bytes: b84cd54000ffe0ad643e6568560b4e7d
timestamp: 2011-09-13 11:04:20

Version Info:

Comments:
CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 3, 0, 0, 0
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2009 QVOD
LegalTrademarks:
OriginalFilename: QvodInstall.exe
PrivateBuild:
ProductName: QvodInstall Module
ProductVersion: 3, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.Generic.6839997 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoad2.38717
MicroWorld-eScanTrojan.Generic.6839997
FireEyeGeneric.mg.b4e2e2d053b377bc
CAT-QuickHealDownloader.Agent.20170
ALYacTrojan.Generic.6839997
CylanceUnsafe
ZillyaDownloader.Agent.Win32.113900
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.053b37
BitDefenderThetaGen:NN.ZexaF.34646.Gi3fa8OlWheb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.BGSB
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R035C0OIB22
ClamAVWin.Trojan.Banker-8527
KasperskyTrojan-Downloader.Win32.Agent.gxwq
BitDefenderTrojan.Generic.6839997
NANO-AntivirusTrojan.Win32.Agent.bddwuk
AvastWin32:Trojan-gen
TencentTrojan.Win32.Qvod.aab
Ad-AwareTrojan.Generic.6839997
TACHYONTrojan-Downloader/W32.Agent.524576.B
EmsisoftTrojan.Generic.6839997 (B)
ComodoTrojWare.Win32.Downloader.Agent.gxwq@4oscoe
BaiduWin32.Trojan-Dropper.Agent.s
VIPRETrojan.Generic.6839997
TrendMicroTROJ_GEN.R035C0OIB22
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Mal/MDrop-IL
IkarusVirus.Win32.Jadtre
GDataTrojan.Generic.6839997
JiangminTrojanDownloader.Agent.dims
GoogleDetected
AviraTR/Dldr.Agent.gxwqc
Antiy-AVLTrojan/Generic.ASMalwS.13
ViRobotTrojan.Win32.A.Downloader.524576.G
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Swisyn.R14071
Acronissuspicious
McAfeeGenericRXAA-AA!B4E2E2D053B3
MAXmalware (ai score=89)
VBA32BScope.Trojan.Ymacco
MalwarebytesNimnul.Virus.FileInfector.DDS
RisingTrojan.Win32.AVplayer.w (CLASSIC)
YandexTrojan.DL.Agent!n5BKrrWRI9k
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.GXWQ!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.6839997?

Trojan.Generic.6839997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment