Trojan

Trojan.Generic.9920245 removal tips

Malware Removal

The Trojan.Generic.9920245 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.9920245 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Created a process from a suspicious location
  • Harvests cookies for information gathering

How to determine Trojan.Generic.9920245?


File Info:

name: 9840B2150C2C802F8D74.mlw
path: /opt/CAPEv2/storage/binaries/73b33f93d55a85709ad9e1010efc040330eb65c68bc759beb30e542ac7987d0c
crc32: E9222544
md5: 9840b2150c2c802f8d7404fce80695af
sha1: 47cd544f48931bf3f9e98b53e6f814d8aa2a4017
sha256: 73b33f93d55a85709ad9e1010efc040330eb65c68bc759beb30e542ac7987d0c
sha512: eb7e988b0241877994a04dbe2f7d692bab0692aaf488064feac33f43de390eb4a0c8f962c63c6fe632c0588191e1d3b62f800b4eefd31716391301fd5d00390f
ssdeep: 24576:/wlBrygOW3UhoYNrWicJ3IJ3zsM3Y8tA4jq1roQcgPZ6EBVwTGETJsjrizEQke3k:u53e3Ho6njVRgR62wiE+jxQkeJa6g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD753315F7DE9B91F1508A3627DCDBC030E026E6EDA42ED35B0D211B0775EE4E63622A
sha3_384: d123cee8f9266e3183efe5efaaefb6f9c105c9736ce56b9696330584582d00c49061ea32f7b96b1ed0547b61b2777063
ep_bytes: 60be001046008dbe0000faff57eb0b90
timestamp: 2007-11-25 09:21:46

Version Info:

FileDescription:
FileVersion: 3, 2, 10, 0
CompiledScript: AutoIt v3 Script : 3, 2, 10, 0
Translation: 0x0809 0x04b0

Trojan.Generic.9920245 also known as:

LionicTrojan.Win32.Agent.lwaI
MicroWorld-eScanTrojan.Generic.9920245
FireEyeTrojan.Generic.9920245
McAfeeArtemis!9840B2150C2C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
Cybereasonmalicious.50c2c8
CyrenW32/Risk.PJKJ-5353
SymantecSecurityRisk.gen1
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Buzus-7648
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Generic.9920245
AvastWin32:Dropper-gen [Drp]
Ad-AwareTrojan.Generic.9920245
ComodoTrojWare.Win32.TrojanDownloader.Agent.czojg@1skn3s
DrWebTrojan.Siggen2.17369
ZillyaDropper.KGen.Win32.5973
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.Generic.9920245 (B)
GDataTrojan.Generic.9920245
KingsoftWin32.Malware.Heur_Generic.B.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.Generic.9920245
MAXmalware (ai score=89)
YandexTrojan.DR.KGen!N503tEks12M
WebrootW32.Malware.Gen
AVGWin32:Dropper-gen [Drp]

How to remove Trojan.Generic.9920245?

Trojan.Generic.9920245 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment