Trojan

Trojan.GenericFC.S6052159 removal instruction

Malware Removal

The Trojan.GenericFC.S6052159 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericFC.S6052159 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

mish305.hopto.org

How to determine Trojan.GenericFC.S6052159?


File Info:

crc32: 6E847B8E
md5: a298597d41621d8b4e4be26a07f6a455
name: upload_file
sha1: 700cb93ebe3aa96024140b5298a60cb91319c0d8
sha256: 207c13ebba8fff7feb175a9ea7cd130b3030569ed39de10032673a69f0a6b990
sha512: a3857b7414ca37451d0b6191af1362c6f075b0b8f128724f9dcd52ce3df22ccf4c740a65c6ee5e676bcf6bafcf2f6bad7f0b2d0e2831606dd440e0b3da407c4c
ssdeep: 384:M/YIiu7jtD+P3V+y0bBEFYt3vys2wSDrAF+rMRTyN/0L+EcoinblneHQM3epzXM:cdmV10bBEFYt6dwErM+rMRa8NuCZt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan.GenericFC.S6052159 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.35200
MicroWorld-eScanGeneric.MSIL.Bladabindi.04093790
FireEyeGeneric.mg.a298597d41621d8b
CAT-QuickHealTrojan.GenericFC.S6052159
ALYacGeneric.MSIL.Bladabindi.04093790
MalwarebytesBackdoor.NJRat
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Bladabindi.04093790
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d41621
TrendMicroBKDR_BLADABI.SMC
BitDefenderThetaGen:NN.ZemsilF.34254.cmX@aWQk6hb
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:Bladabindi-JK [Trj]
ClamAVWin.Trojan.B-468
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
ViRobotBackdoor.Win32.Agent.37888.AL
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.04093790
SophosTroj/Bbindi-W
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
F-SecureTrojan.TR/Dropper.Gen
BaiduMSIL.Backdoor.Bladabindi.a
InvinceaML/PE-A + Troj/Bbindi-W
McAfee-GW-EditionBehavesLike.Win32.Trojan.nm
EmsisoftGeneric.MSIL.Bladabindi.04093790 (B)
IkarusWorm.MSIL.Bladabindi
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
MicrosoftBackdoor:MSIL/Bladabindi.B
ArcabitGeneric.MSIL.Bladabindi.D3E775E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan-Spy.Bladabindi.BQ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Korat.R207428
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=87)
VBA32Trojan.Downloader
CylanceUnsafe
ZonerTrojan.Win32.84773
ESET-NOD32a variant of MSIL/Bladabindi.AR
TrendMicro-HouseCallBKDR_BLADABI.SMC
YandexTrojan.AvsMofer.dd6520
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.334C.Malware.Gen

How to remove Trojan.GenericFC.S6052159?

Trojan.GenericFC.S6052159 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment