Trojan

Trojan.GenericFC.S16691458 (file analysis)

Malware Removal

The Trojan.GenericFC.S16691458 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericFC.S16691458 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

ip-api.com
salivary-senses.000webhostapp.com

How to determine Trojan.GenericFC.S16691458?


File Info:

crc32: 672A613F
md5: aa800634b57f5faad88bfecc9b5ac6ca
name: AA800634B57F5FAAD88BFECC9B5AC6CA.mlw
sha1: 9d2baf59df2a6f9b320833bfad8b1c1299ed9d18
sha256: e6beb296cff4c2d4f1a937ad63e631ed33c3573172dc62ebc873fa9fe9f205a0
sha512: 789753c3d437f2f8695dd2382539f2a4f704112a94eb7ffcc58af5fa4305bbcfd26c8a7ff49f361f6743e0aff787e26730c8bf34a4864fc9d84225dfef4a6b76
ssdeep: 12288:cy902sbD6GpoCrMt6aA/RUBi3vxTTGBRLuL:cyMXVrxZ6+JTK6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.10240.16384 (th1.150709-1700)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.10240.16384
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan.GenericFC.S16691458 also known as:

K7AntiVirusSpyware ( 004bd3191 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.18353
CynetMalicious (score: 99)
CAT-QuickHealTrojan.GenericFC.S16691458
ALYacTrojan.GenericKD.36225208
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1322579
SangforTrojan.Win32.Generic.ky
AlibabaTrojanBanker:MSIL/ClipBanker.9968f92a
K7GWSpyware ( 004bd3191 )
Cybereasonmalicious.4b57f5
CyrenW32/Perseus.T.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
ZonerTrojan.Win32.60682
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Clipbanker-9782972-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.36225208
NANO-AntivirusTrojan.Win32.KeyLogger.dklttv
MicroWorld-eScanTrojan.GenericKD.36225208
TencentWin32.Trojan.Generic.Lohk
Ad-AwareTrojan.GenericKD.36225208
SophosMal/Generic-S
ComodoMalware@#tsbgzlfuyehr
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.PASSTEAL.SMD1
McAfee-GW-EditionGenericRXJL-MW!8D47469FB45D
FireEyeGeneric.mg.aa800634b57f5faa
EmsisoftTrojan.GenericKD.36225208 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Banker.MSIL.asn
AviraHEUR/AGEN.1106072
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22AB4F5
MicrosoftTrojan:MSIL/ClipBanker.A!MTB
GDataMSIL.Trojan.Clipbanker.L
McAfeeArtemis!AA800634B57F
MAXmalware (ai score=89)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTrojanSpy.MSIL.PASSTEAL.SMD1
RisingSpyware.ClipBanker!1.C5DA (CLASSIC)
YandexTrojan.Agent!9wgTP2mqT/I
FortinetMSIL/SpyPSW.AVQ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan.GenericFC.S16691458?

Trojan.GenericFC.S16691458 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment