Trojan

Trojan.Generic.7861975 malicious file

Malware Removal

The Trojan.Generic.7861975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.7861975 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to stop active services
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.7861975?


File Info:

name: F18D537B7C87A5A160EB.mlw
path: /opt/CAPEv2/storage/binaries/8e20e6607c9661ce9af567e127b9b426f16a2b0d12354fedeebd7ea42e680161
crc32: 0EE0BD21
md5: f18d537b7c87a5a160eb9074d21f92da
sha1: 072572657c78768a30da9630125b1ad5ef1473c5
sha256: 8e20e6607c9661ce9af567e127b9b426f16a2b0d12354fedeebd7ea42e680161
sha512: 5e6fdf48df5e25dbbf8e3b5b42ec49e7ea659bab9cee29bf8e5b71aa42ae3fa52b478ba1cb0f304aefea7591853f7643be150b2946ff510a852fc6f27edea269
ssdeep: 6144:sr6WMMmZZThl14nDWgRAkP79GQn8xID0DMFAzJvFMH6KsGr:sr6QmgR3P79GLxe0DVjq6Ksu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D6423CB499C31C0FB689E718823156E976B1D656E7D2C992BBDF0243E37A8DF284503
sha3_384: 30271cf89ce6bd560ffe5edb11badb76595ba7195a524b9e427354338fae51fa8d014758bca1c2f2d1374e301b2369c8
ep_bytes: 558bec6aff687031400068102c400064
timestamp: 2009-09-17 11:25:47

Version Info:

0: [No Data]

Trojan.Generic.7861975 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Magania.l4B3
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.7861975
FireEyeGeneric.mg.f18d537b7c87a5a1
ALYacTrojan.Generic.7861975
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b7c87a
VirITTrojan.Win32.Generic.CNBI
CyrenW32/PcClient.O.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/Agent.OFV
APEXMalicious
ClamAVWin.Spyware.84307-2
KasperskyTrojan-GameThief.Win32.Magania.daup
BitDefenderTrojan.Generic.7861975
NANO-AntivirusTrojan.Win32.Magania.ecavtq
AvastWin32:Dropper-BKV [Trj]
TencentMalware.Win32.Gencirc.10bbf321
Ad-AwareTrojan.Generic.7861975
SophosMal/Redos-H
ComodoTrojWare.Win32.Magania.~all@f80ty
DrWebTrojan.Inject.6805
ZillyaTrojan.Pincav.Win32.5709
TrendMicroTROJ_PINCAV_0000003.TOMA
McAfee-GW-EditionBehavesLike.Win32.Sivis.fc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.7861975 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.7861975
JiangminTrojan/Dialer.iff
AviraTR/Spy.Gen
ArcabitTrojan.Generic.D77F6D7
ViRobotTrojan.Win32.Pincav.309843
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Ressdt.R74
McAfeeGenericR-HRF!F18D537B7C87
MAXmalware (ai score=89)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.3094314273
TrendMicro-HouseCallTROJ_PINCAV_0000003.TOMA
RisingBackdoor.Win32.RemoteC.aj (CLASSIC)
YandexTrojan.GenAsa!jrcYIW/gId0
IkarusTrojan-PWS.Win32.Alipay
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Pincav.BVK!tr
BitDefenderThetaAI:Packer.58996C4E1F
AVGWin32:Dropper-BKV [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.7861975?

Trojan.Generic.7861975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment