Trojan

Trojan.Generic.9953347 (file analysis)

Malware Removal

The Trojan.Generic.9953347 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.9953347 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Harvests cookies for information gathering

How to determine Trojan.Generic.9953347?


File Info:

name: 56EB3E2F361AF67E1961.mlw
path: /opt/CAPEv2/storage/binaries/510f2e18f1f081039bc4cd38b61ba456432a3b9b6dcaed0c5205f2815225b8cb
crc32: 4C6018F2
md5: 56eb3e2f361af67e19612d99b2aacf9a
sha1: 94caf565a46f374f8487126af07d4813340b530b
sha256: 510f2e18f1f081039bc4cd38b61ba456432a3b9b6dcaed0c5205f2815225b8cb
sha512: 8390a7ab5a342044e7bd1c458ef071132fc166a8829ca972f1272be65be57c18612e4c10a19cbf6dcd16faee3c0a5c2266e0530964ca8f2cc0fe978d95577400
ssdeep: 6144:Ke34eavUh7lthEsO65TCaO+fHwsVxdTp59Rkd:nauRthDTRMuHwsvT5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F054F10133D0C9B7CAB90D70D87386F15B75AD92D32186774380BE6E7E723528D25ABA
sha3_384: dcf809f9946b8af669c64a72e188b57d1eb3e3ced412ef0cf4afcadc6f1723115b589de33cb683d7d2d674143df0211e
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-06-29 09:54:52

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.1.1.0
InternalName: no_ipsetup_v4_0_1.exe
LegalCopyright:
OriginalFilename: no_ipsetup_v4_0_1.exe
ProductVersion: 1.1.1.0
Assembly Version: 1.1.1.0

Trojan.Generic.9953347 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.DownLoader9.40274
MicroWorld-eScanTrojan.Generic.9953347
FireEyeGeneric.mg.56eb3e2f361af67e
ALYacTrojan.Generic.9953347
CylanceUnsafe
Sangfor[NULLSOFT PIMP INSTALL SYSTEM2]
K7AntiVirusTrojan ( 700000121 )
AlibabaRansom:Win32/Blocker.0156f12b
K7GWTrojan ( 700000121 )
Cybereasonmalicious.f361af
BitDefenderThetaGen:NN.ZemsilF.34638.rq0@a0g2DQh
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.BB
TrendMicro-HouseCallRansom_Blocker.R002C0WDS22
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.bwkw
BitDefenderTrojan.Generic.9953347
NANO-AntivirusTrojan.Win32.Dwn.dkkqfv
AvastWin32:Trojan-gen
TencentWin32.Trojan.Blocker.Syil
Ad-AwareTrojan.Generic.9953347
EmsisoftTrojan.Generic.9953347 (B)
ComodoMalware@#2c5gmm5gpkhyv
TrendMicroRansom_Blocker.R002C0WDS22
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosGeneric ML PUA (PUA)
IkarusTrojan.BAT.Runner
GDataTrojan.Generic.9953347
JiangminTrojan.Blocker.qrp
AviraHEUR/AGEN.1236703
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D97E043
ViRobotTrojan.Win32.Z.Blocker.285184
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 99)
McAfeeArtemis!56EB3E2F361A
VBA32Trojan.MSIL.gen.a.5
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.WW!tr.dldr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Generic.9953347?

Trojan.Generic.9953347 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment