Trojan

Trojan.GenericRI.S19154279 removal instruction

Malware Removal

The Trojan.GenericRI.S19154279 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S19154279 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.waaer435fc.com

How to determine Trojan.GenericRI.S19154279?


File Info:

crc32: 049DE6A0
md5: cc31153d67b2ff521842e5e979b7b90a
name: CC31153D67B2FF521842E5E979B7B90A.mlw
sha1: 7b18e17770cbf301afe352b0ddaf276b9c6b6b2a
sha256: 37376d4980485fdc2c95d50bb133a969164420be1c527f629049e747f36c026f
sha512: 8c69f9b46e821ca064ebfaf17cdb8327f6a0f885a524ef168efc9bd2b8eb7f910dad3384af3df3243bd757ba305a1638cab182e11f6b8c3f39f40229f9b9c46e
ssdeep: 12288:VOOfN590uu6opX+t4sPa3UoG1q9ViNQJm3d5/TdPwNd13NVmGx:YOfNkuu6oLsykoGYw3bBPwNXNVmGx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.GenericRI.S19154279 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusPassword-Stealer ( 00574a681 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S19154279
ALYacGen:Variant.Razy.745231
K7GWPassword-Stealer ( 00574a681 )
Cybereasonmalicious.d67b2f
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Fbkatz-9833093-0
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.Razy.745231
NANO-AntivirusTrojan.Win32.Fbkatz.ihzmsf
MicroWorld-eScanGen:Variant.Razy.745231
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34722.SyW@aGFesCpi
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.cc31153d67b2ff52
EmsisoftTrojan-PSW.Agent (A)
JiangminTrojanSpy.Fbkatz.g
AviraHEUR/AGEN.1138963
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataGen:Variant.Razy.745231
McAfeeGenericRXNE-CG!4915242C4106
MAXmalware (ai score=81)
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:y7CnJnqDA1GnKTVXfSQh2g)
IkarusTrojan.MSIL.Confuser
AVGWin32:PWSX-gen [Trj]

How to remove Trojan.GenericRI.S19154279?

Trojan.GenericRI.S19154279 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment