Trojan

Should I remove “Trojan.Generic.7969466”?

Malware Removal

The Trojan.Generic.7969466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.7969466 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Clears web history

How to determine Trojan.Generic.7969466?


File Info:

name: E479C546F893426C8EC4.mlw
path: /opt/CAPEv2/storage/binaries/7abc75b719a90a2188fc37dea77c08beabce6c1e81ab851e0ced83104531e336
crc32: D14D0A2C
md5: e479c546f893426c8ec4bf1ee694ff26
sha1: 03c62740d3acffb35c835222baa9112b49bc3099
sha256: 7abc75b719a90a2188fc37dea77c08beabce6c1e81ab851e0ced83104531e336
sha512: 9e65715298eb0b4ff9a7b8aae7f755c8acc10a049f827fa7000c69292f2a2e8d227d3132be8375c88b9fb504de224c1d6c1a797f9fcb36ecc3713a5fadfd1a80
ssdeep: 3072:eyykpR1Uz4FmBkLO0P9WrkF16YLkYJwBig/Ke14ZMSkW5OEr:/yAmzlB6fWrU1/LkdiK10v53
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118D3121DA517E099FAFB95761C232B259D5DF268463B380B4CF43C7D08EA0D46E02E97
sha3_384: 082e2bff1b22101de93ed253cc9bddfe9a75b8b6704057a81fbbab86ec7cdddae63ad314c7ccb679a66abb6e205c0639
ep_bytes: 60be00a041008dbe0070feff5783cdff
timestamp: 2005-03-31 00:03:56

Version Info:

CompanyName: AVG Technologies CZ, s.r.o.
FileDescription: AVG Tray Monitor
FileVersion: 9.0.0.871
InternalName: avgtray
LegalCopyright: Copyright © 2010 AVG Technologies CZ, s.r.o.
OriginalFilename: avgtray.exe
ProductName: AVG Internet Security
ProductVersion: 9.0.0.871
PrivateBuild: Win32 Release_Unicode
SpecialBuild: Avg8VC8_2010_1109_133319(871), SVNRev 145063 (/branches/release/SmallUpdate9-12)
Translation: 0x0409 0x04e4

Trojan.Generic.7969466 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Generic.lh2q
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e479c546f893426c
McAfeeGenericRXAA-AA!E479C546F893
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.44563
SangforTrojan.Win32.Zbot.ZA
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanPSW:Win32/Kryptik.46751eec
K7GWTrojan ( f1000f011 )
CrowdStrikewin/malicious_confidence_60% (W)
VirITTrojan.Win32.Packed.BFTR
CyrenW32/Risk.TQYG-8598
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.LPD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1279
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.7969466
NANO-AntivirusTrojan.Win32.Zbot.bvzbk
ViRobotTrojan.Win32.Zbot.133632.G
MicroWorld-eScanTrojan.Generic.7969466
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Ajlh
Ad-AwareTrojan.Generic.7969466
EmsisoftTrojan.Generic.7969466 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
DrWebTrojan.Packed.21467
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
CMCGeneric.Win32.e479c546f8!CMCRadar
SophosML/PE-A + Mal/FakeAV-IU
IkarusTrojan.Win32.Broperk
GDataTrojan.Generic.7969466
JiangminTrojanSpy.Zbot.avlr
WebrootW32.Infostealer.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Malware.Heur_Generic.B.(kcloud)
ArcabitTrojan.Generic.D799ABA
SUPERAntiSpywareTrojan.Agent/Gen-FakeAVG
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
AhnLab-V3Trojan/Win32.FraudPack.R3415
BitDefenderThetaGen:NN.ZexaF.34212.imKfa0xTQvcc
ALYacTrojan.Generic.7969466
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingWorm.Kolab!8.1C4D (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1695184.susgen
FortinetW32/Kryptik.NAS!tr
AVGWin32:Trojan-gen
PandaBck/Qbot.AO

How to remove Trojan.Generic.7969466?

Trojan.Generic.7969466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment