Trojan

About “Trojan.Generic.KDZ.2848” infection

Malware Removal

The Trojan.Generic.KDZ.2848 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.KDZ.2848 virus can do?

  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Trojan.Generic.KDZ.2848?


File Info:

name: 4585AB21CDA2FE423663.mlw
path: /opt/CAPEv2/storage/binaries/24592b881440b004bfcc51692deef734babdfc0cd5719826bd05ae678584bfb9
crc32: DA1D0B14
md5: 4585ab21cda2fe423663d798a52baf9b
sha1: b5a9b0c35d25b6a7d1b5478da55f571aece5f2d8
sha256: 24592b881440b004bfcc51692deef734babdfc0cd5719826bd05ae678584bfb9
sha512: b46abc2df4abbd015bf8f11d3969aba34b94a7c3ed237abc0d99be2009fea6446c6a63e0a788d8e7dbfb0445b332ec956b35941c5bb1aaa0e2aa5ffc155bc6e4
ssdeep: 1536:rX3F7wWqPyIMNt6+4aQQg3dTXVyaH8g6C2zzl:rXxwOlLQLGahl6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A493CEC6D5856768EC9E0C3DC713F0A699236E2E71DDC0AA11237AF84EBF344426859F
sha3_384: 7e68a5b0cdb952ddca802e5807fb763162b46fb2da22fbb82f0ab53b27955fea379d723785fde1f9d82ffe9db03988a0
ep_bytes: 64a100000000558bec6aff6860204000
timestamp: 2012-12-27 12:12:26

Version Info:

0: [No Data]

Trojan.Generic.KDZ.2848 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.KDZ.2848
ALYacTrojan.Generic.KDZ.2848
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Tofsee.4c38240c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1cda2f
VirITTrojan.Win32.Generic.BYLW
CyrenW32/S-303308cc!Eldorado
ESET-NOD32Win32/Agent.OBA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.KDZ.2848
NANO-AntivirusTrojan.Win32.Spambot.bfqzjr
AvastWin32:Reveton-LG [Trj]
TencentMalware.Win32.Gencirc.114bc178
Ad-AwareTrojan.Generic.KDZ.2848
EmsisoftTrojan.Generic.KDZ.2848 (B)
ComodoMalware@#3dicyjlmu47mn
DrWebTrojan.Spambot.11176
ZillyaTrojan.Gimemo.Win32.4633
TrendMicroTROJ_SPNR.1ABP13
McAfee-GW-EditionGenericR-OOF!4585AB21CDA2
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.4585ab21cda2fe42
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Generic.KDZ.2848
JiangminTrojan/Gimemo.fdo
WebrootW32.Pdf.Exploit
AviraTR/Rogue.KD.818059
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.A.Gimemo.93555
MicrosoftBackdoor:Win32/Tofsee.F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gimemo.R49601
McAfeeGenericR-OOF!4585AB21CDA2
MAXmalware (ai score=100)
VBA32BScope.Trojan.Occamy
TrendMicro-HouseCallTROJ_SPNR.1ABP13
RisingTrojan.Generic@AI.84 (RDML:f/dCCsb0XPa2SObGpRwUlg)
YandexTrojan.Agent!1f+vnCTqhr0
IkarusTrojan-Ransom.Gimemo
MaxSecureTrojan.Malware.5031357.susgen
FortinetW32/Kryptik.AREG!tr
BitDefenderThetaGen:NN.ZexaF.34712.fqZ@a0S1A0oc
AVGWin32:Reveton-LG [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Generic.KDZ.2848?

Trojan.Generic.KDZ.2848 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment