Trojan

Trojan.Generic.KDZ.2789 (file analysis)

Malware Removal

The Trojan.Generic.KDZ.2789 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.KDZ.2789 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Trojan.Generic.KDZ.2789?


File Info:

name: 1CDE8D44E9DF8F69DA9A.mlw
path: /opt/CAPEv2/storage/binaries/725774fd35005739c7b2969062f0ed0aa6eee65ae18044f69c28429757dbae4e
crc32: 54DD6E6E
md5: 1cde8d44e9df8f69da9a5b0865cd31fe
sha1: bf2b33be2253615862099e3b315648eb3a410fcd
sha256: 725774fd35005739c7b2969062f0ed0aa6eee65ae18044f69c28429757dbae4e
sha512: be61d7989f0a70232b78762ceeecbaa91d722ca8acc4635f196b047c3a9b73033f9c4fea0ca6c73c9665a6ca9aaf1186661ad8154ed3f5abe917b1ab6f0c14be
ssdeep: 12288:Gp54CMg0+VNsCzJdKa/lwICHOAYDeUWKN5QYUr6pzTFwL6oumThTiHiW8KwMGtlu:a5FMD+VSCzJdJ/lwaLN5xpz6L6/mThTs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181F4230A89849D7DF518ED3EC9B3404E43365D273DD90D72F6A0B27C0876B97902BA7A
sha3_384: 8fc29046f08d55d02c63da2781bd77698103cbb4ea0e303618f4cd465cb28a99adb7b5f5e47285a788ab0e3fc50044d2
ep_bytes: 8d3d023040008d35b01f40006a7459f3
timestamp: 2012-12-12 07:12:33

Version Info:

0: [No Data]

Trojan.Generic.KDZ.2789 also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.Generic.KDZ.2789
MalwarebytesGeneric.Rogue.Fake.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.4e9df8
CyrenW32/FakeAlert.WL.gen!Eldorado
SymantecSecShieldFraud!gen10
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ATSS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Tepfer-635
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.KDZ.2789
NANO-AntivirusTrojan.Win32.Panda.crensc
MicroWorld-eScanTrojan.Generic.KDZ.2789
AvastWin32:FakeAV-EGN [Trj]
TencentWin32.Trojan.Generic.Kqil
Ad-AwareTrojan.Generic.KDZ.2789
SophosML/PE-A + Troj/Zbot-DJX
ComodoBackdoor.Win32.Kelihos.G@5h79xe
DrWebBackDoor.Slym.1367
VIPRETrojan.Generic.KDZ.2789
TrendMicroBKDR_KELIHOS.SM
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1cde8d44e9df8f69
EmsisoftTrojan.Generic.KDZ.2789 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.KDZ.2789
JiangminTrojan/Tepfer.Gen
AviraTR/Winwebsec.559874
ArcabitTrojan.Generic.KDZ.DAE5
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R48391
Acronissuspicious
McAfeeBackDoor-FJW
MAXmalware (ai score=100)
VBA32Malware-Cryptor.SB.01722
CylanceUnsafe
TrendMicro-HouseCallBKDR_KELIHOS.SM
RisingTrojan.Bulta!8.35D (TFE:3:dXwsk3TrwhF)
YandexTrojan.GenAsa!aDYMBjS7qKE
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
BitDefenderThetaGen:NN.ZexaF.34726.UqW@am!8agh
AVGWin32:FakeAV-EGN [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Generic.KDZ.2789?

Trojan.Generic.KDZ.2789 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment