Trojan

Trojan.GenericCS.S1024161 (file analysis)

Malware Removal

The Trojan.GenericCS.S1024161 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericCS.S1024161 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects VirtualBox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a registry key or value with NUL characters to avoid detection with regedit
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Attempts to identify installed analysis tools by registry key
  • Attempts to identify installed AV products by installation directory
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Detects Virtual PC through the presence of a file
  • Attempts to modify browser security settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.GenericCS.S1024161?


File Info:

crc32: 22359914
md5: 3cf83ee9b1eca7399241843618e9ea5e
name: exe1.exe
sha1: 06e41c2587ab8235c6782cf1af589099a6242666
sha256: f5be23df0cfd529674c9939bf11e4d0f61693f898cf989e7b7acf62202c0874e
sha512: eeb6ea9a7c9c8b794a5603238c07f701b389bf9594be849f38ae500b41615231f9728c48586895d6c4912c1ecad6076a19b88631cbfde2e31ceb45087afab36d
ssdeep: 6144:C9oXC7GqcqR9SptLvc6JYVdz6zxV7roeS1SDDqexyBnbjcB8cxBdtcwCcML8mX/2:ZiG7e9SpJvcoYPIzfU1SryRUXxztcdyZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001-2015 by (Canada) Ltd.
InternalName: PDF-Change
FileVersion: 2.5.0314
FileDescription: PDF-Change
SpecialBuild:
CompanyName: polion
LegalTrademarks: Tracker (Canada) Ltd.
Comments: PDF-Change
ProductName: PDF-Change
ProductVersion: 2.5
PrivateBuild:
OriginalFilename: polion.exe
Translation: 0x0415 0x04e2

Trojan.GenericCS.S1024161 also known as:

MicroWorld-eScanTrojan.GenericKD.32002565
FireEyeGeneric.mg.3cf83ee9b1eca739
CAT-QuickHealTrojan.GenericCS.S1024161
ALYacTrojan.GenericKD.32002565
CylanceUnsafe
VIPRETrojan.Win32.Kovter.ab (v)
AegisLabTrojan.Win32.Poweliks.4!c
SangforMalware
K7AntiVirusTrojan ( 0050e3561 )
BitDefenderTrojan.GenericKD.32002565
K7GWTrojan ( 0050e3561 )
Cybereasonmalicious.9b1eca
Invinceaheuristic
F-ProtW32/Kovter.T.gen!Eldorado
SymantecRansom.Kovter
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Kovter-6333830-0
GDataTrojan.GenericKD.32002565
KasperskyTrojan.Win32.Poweliks.zwb
AlibabaTrojan:Win32/Poweliks.c526a81f
NANO-AntivirusTrojan.Win32.Poweliks.epddwv
RisingTrojan.Kovter!8.152 (TFE:1:ySZSfbQGCXH)
Ad-AwareTrojan.GenericKD.32002565
EmsisoftTrojan.GenericKD.32002565 (B)
ComodoMalware@#s1ppyg5m45s5
F-SecureHeuristic.HEUR/AGEN.1018722
DrWebTrojan.SpyBot.702
ZillyaTrojan.Poweliks.Win32.920
TrendMicroTROJ_HPKOVTER.SMAX1
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
SophosMal/Kovter-Z
IkarusTrojan.Win32.Kovter
CyrenW32/Kovter.T.gen!Eldorado
JiangminTrojan.Poweliks.zy
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1018722
Antiy-AVLTrojan/Win32.Poweliks
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E85205
ZoneAlarmTrojan.Win32.Poweliks.zwb
MicrosoftTrojan:Win32/Kovter!rfn
TACHYONTrojan/W32.Poweliks.418218
AhnLab-V3Trojan/Win32.Poweliks.R201039
Acronissuspicious
McAfeeGenericRXBP-QR!3CF83EE9B1EC
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.AHIV
TrendMicro-HouseCallTROJ_HPKOVTER.SMAX1
YandexTrojan.Poweliks!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/GenKryptik.AJNV!tr
BitDefenderThetaGen:NN.ZexaF.33558.zG1@aaNHTpmH
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.704

How to remove Trojan.GenericCS.S1024161?

Trojan.GenericCS.S1024161 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment