Trojan

Trojan.Generic.TRFH379 (file analysis)

Malware Removal

The Trojan.Generic.TRFH379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.TRFH379 virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Generic.TRFH379?


File Info:

name: 74DA9B655F8E795ED676.mlw
path: /opt/CAPEv2/storage/binaries/756c41055cc1a7363205dfcfffa157efb467fe2aa176ba4c2c234cd554815ae6
crc32: 503C8F49
md5: 74da9b655f8e795ed676996712620642
sha1: 875dab7e79fee8449cb42c7e9dcb887ce1f7b73c
sha256: 756c41055cc1a7363205dfcfffa157efb467fe2aa176ba4c2c234cd554815ae6
sha512: 4f35a8c1b704cc4e259f7be82eac6fae8a9f717183d5632274c5b03ac44ef9cc613b30200c19baef2d8b00aaf5fee22592d6806e149ba1e55a822b18b3cc7849
ssdeep: 98304:B+ARHOPr9N6Q/15powG92O8MDML+qy66I5tLF6s7yv/kE:Bruz9oQ/15p4UNMDMSvdWxtO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8F5330692CA44AFDF56C2B76FF9BFD830F5B4445CD4A8DADC0800164EB216F75399A2
sha3_384: 50a733eb1c80086eb3b621502cf75d0124989e68d760eb3b9fc335866edea0427f5103fda4dc229e39fd11c5a4a935a6
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-05-21 12:44:26

Version Info:

Translation: 0x0000 0x04b0
Comments: Token Stealer Builder By D-V
CompanyName: Token Stealer Builder By D-V
FileDescription: Token Stealer Builder By D-V
FileVersion: 1.0.0.0
InternalName: Token Stealer Builder By D-V1.exe
LegalCopyright: Copyright © 2022
OriginalFilename: Token Stealer Builder By D-V1.exe
ProductName: Token Stealer Builder By D-V
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.Generic.TRFH379 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanTrojan.GenericKD.39735324
FireEyeGeneric.mg.74da9b655f8e795e
CAT-QuickHealTrojan.Generic.TRFH379
ALYacTrojan.GenericKD.39735324
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00568ce41 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 00568ce41 )
Cybereasonmalicious.55f8e7
CyrenW32/MSIL_Kryptik.CQL.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EVL
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.APosT.gen
BitDefenderTrojan.GenericKD.39735324
NANO-AntivirusTrojan.Win32.Disco.jozswi
TencentMsil.Trojan-dropper.Agent.Ajcc
Ad-AwareTrojan.GenericKD.39735324
SophosMal/Generic-S
ComodoMalware@#8s1qmq2b5zte
DrWebTrojan.MulDropNET.12
ZillyaDropper.Agent.Win32.495670
TrendMicroTROJ_GEN.R002C0DEL22
McAfee-GW-EditionBehavesLike.Win32.Fareit.wc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.39735324 (B)
Paloaltogeneric.ml
AviraHEUR/AGEN.1235225
MicrosoftTrojan:MSIL/Nanocore.SDSD!MTB
GDataTrojan.GenericKD.39735324
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4140848
Acronissuspicious
McAfeePWS-FCUQ!74DA9B655F8E
MAXmalware (ai score=86)
VBA32Trojan.MulDropNET
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallTROJ_GEN.R002C0DEL22
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:qrumMQ6HAQpxeo4itEdMIQ)
YandexTrojan.APosT!QY34MJwZE8M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74418669.susgen
FortinetMSIL/CoinMiner.ELXR!tr
BitDefenderThetaGen:NN.ZemsilF.34712.tp0@au!yEjh
AVGWin32:RATX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.TRFH379?

Trojan.Generic.TRFH379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment