Trojan

Trojan.Generic.S1889037 (file analysis)

Malware Removal

The Trojan.Generic.S1889037 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.S1889037 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

wpad.local-net
www.cheathappens.com

How to determine Trojan.Generic.S1889037?


File Info:

name: 96DE614382C180D36B14.mlw
path: /opt/CAPEv2/storage/binaries/3d7f5e4b27eac1af3d03b532302af428cc28fd92660b9a5d58d105756b7f0416
crc32: FBE8B200
md5: 96de614382c180d36b1416c81ef3f87e
sha1: 5b1345dd93d92add7cd2e8b869af9c7f4c5128d9
sha256: 3d7f5e4b27eac1af3d03b532302af428cc28fd92660b9a5d58d105756b7f0416
sha512: 4bc3896108f450f397027b42a89bcb50ee4d4750319bc8b65ebb2bbef5bd1a05840f02218edca4b505508c1b3bd16861ab16556cd765b2c8eee5565dd6b48138
ssdeep: 49152:pU4T2Q4hoqmwSdhowrBJXThgUxxaLciUJBV1Ls2wBPJBV1Ls2wBU:pU3hoqOhJDvMVsU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11FA5BF46A2A051DDE6E3C179C262A327EA31742D07209BDB63E44BF66B13ED09F3D351
sha3_384: bad0da2c55f53c0ce2a9a0f582f6d2214052674c88f2598a591190ae61d5c495df348eeb2d7d1511738e234fb4800e84
ep_bytes: 68a8000000680000000068505b6000e8
timestamp: 2018-06-26 01:45:01

Version Info:

0: [No Data]

Trojan.Generic.S1889037 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Game.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.96de614382c180d3
CAT-QuickHealTrojan.Generic.S1889037
CylanceUnsafe
ZillyaTrojan.GameHack.Win64.207
SangforVirus.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0050cb4e1 )
K7GWUnwanted-Program ( 0050cb4e1 )
BitDefenderThetaGen:NN.ZexaF.34294.fwX@aW9HeQei
CyrenW32/GameHack.AH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.EVN potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CKL21
Paloaltogeneric.ml
CynetMalicious (score: 100)
EmsisoftApplication.GameHack (A)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric PUA FL (PUA)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1145322
Antiy-AVLTrojan/Generic.ASMalwS.26B22FB
GridinsoftRansom.Win32.Occamy.sa
APEXMalicious
GDataWin32.Application.PSE.11423CR
AhnLab-V3PUP/Win32.Helper.R240933
Acronissuspicious
McAfeeGenericRXAA-AA!96DE614382C1
VBA32Trojan.Downloader
RisingPUF.GameHack!1.B348 (CLASSIC)
IkarusTrojan.Win32.Occamy
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GameHack.A7832C08!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Generic.S1889037?

Trojan.Generic.S1889037 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment