Trojan

Trojan.GenericRI.S22016029 removal

Malware Removal

The Trojan.GenericRI.S22016029 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S22016029 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • CAPE detected the WarzoneRAT malware family
  • Accesses or creates Warzone RAT directories and/or files

How to determine Trojan.GenericRI.S22016029?


File Info:

name: E400649BD2020D87ED05.mlw
path: /opt/CAPEv2/storage/binaries/35c313910913e40bb54c401361effea91e8b820321d432babd831a7e93684e51
crc32: 41799147
md5: e400649bd2020d87ed05e5d863949546
sha1: 36c2ee2d87db2511982ae00b78a4f8c8262ce00c
sha256: 35c313910913e40bb54c401361effea91e8b820321d432babd831a7e93684e51
sha512: 4c84caadac1783a89f7fcd7c54304c6340d051f62fcb1aacc971cac7af55f57d22fcfb96338e2b72170d9da7c8181b34a96a70fb7b4b29d8fadab32d06da0555
ssdeep: 1536:h0jP7/L1B5rVmN8sxHv2M28ix8EUaJxWZoB4u0OVE01:K1VmhaH8EFvW+0OVE0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109B39E13F7E54835F3B201B01ABD7E7ACBEDF9700628C49FA394858A2D31946E925397
sha3_384: bf21b914010ec3a12a06b8a03dbd2c5221358a9b0bf8c893fd3ac2333345bb022222f0c1df8f2931fc16568be2cc8f6e
ep_bytes: 558bec83ec4456ff15e84141008bc88a
timestamp: 2020-08-29 06:54:20

Version Info:

0: [No Data]

Trojan.GenericRI.S22016029 also known as:

BkavW32.AndrneLM.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38473273
FireEyeGeneric.mg.e400649bd2020d87
CAT-QuickHealTrojan.GenericRI.S22016029
McAfeeGenericRXLG-SE!E400649BD202
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054d10e1 )
BitDefenderTrojan.GenericKD.38473273
K7GWTrojan ( 0054d10e1 )
Cybereasonmalicious.bd2020
ArcabitTrojan.Generic.D24B0E39
BitDefenderThetaGen:NN.ZexaF.34114.hyW@aC46ikhi
VirITTrojan.Win32.PSWStealer.CPI
CyrenW32/Antiav.INDT-0919
SymantecTrojan Horse
ESET-NOD32Win32/Agent.TJS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.AveMaria-8799014-1
KasperskyTrojan.Win32.Agentb.jiad
AlibabaMalware:Win32/km_2ec7e.None
NANO-AntivirusTrojan.Win32.AntiAV.fljpfv
ViRobotTrojan.Win32.Agent.1392640.E
RisingStealer.AveMaria!1.BA1C (CLASSIC)
Ad-AwareTrojan.GenericKD.38473273
SophosMal/Generic-S + Troj/Mocrt-A
ComodoTrojWare.Win32.AntiAV.VA@81mmki
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.Agent.Win32.1391531
TrendMicroTrojanSpy.Win32.MOCRT.SM
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.eab
WebrootW32.Trojan.Gen
AviraTR/Redcap.ghjpt
Antiy-AVLTrojan/Generic.ASMalwS.2A11D98
KingsoftWin32.Heur.KVMH017.a.(kcloud)
GridinsoftTrojan.Win32.Agent.oa!s1
MicrosoftBackdoor:Win32/Remcos!MTB
GDataWin32.Backdoor.AveMaria.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AveMaria.R263895
VBA32Trojan.Agentb
ALYacTrojan.PSW.AveMaria
TACHYONTrojan/W32.WarzoneRat.115712
MalwarebytesBackdoor.AveMaria
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.MOCRT.SM
TencentMalware.Win32.Gencirc.10ce4ea1
YandexTrojan.GenAsa!++8lN4UW0KE
MAXmalware (ai score=86)
eGambitTrojan.Generic
FortinetW32/Agent.TJS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.GenericRI.S22016029?

Trojan.GenericRI.S22016029 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment