Trojan

Trojan.GenericRI.S26141407 (file analysis)

Malware Removal

The Trojan.GenericRI.S26141407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S26141407 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan.GenericRI.S26141407?


File Info:

name: 73726C7AD018C36E7482.mlw
path: /opt/CAPEv2/storage/binaries/f18889ea7049b0a0e3b016bf312b94d4985959ad0865d51fa59f18f250effd6d
crc32: E40A2A43
md5: 73726c7ad018c36e7482dea7a8c8a500
sha1: a0411b79c7352f1a68ab22aec4fbb2f56b77e85d
sha256: f18889ea7049b0a0e3b016bf312b94d4985959ad0865d51fa59f18f250effd6d
sha512: d08a93289b8d04901d1864e3330caff03f1d60a077514c90b802ae99f289c1866544d4b12c4bc5763ce1106333f517ef62ea97c266c4d71d1e41959d6d896148
ssdeep: 6144:IH8RV9AOw8xykx1QZbhq45Rp2QSIvVW4UuoqHXAObNVa:I4mX8xDx1QZbB5GQ/VIuoq3Vfa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T199347C2175A2C436D4B2113114F8ABB5C57EB8254B6149EF63D40F3EDE316E3AA31E3A
sha3_384: a3f93cf3a2a003110604a5facf98fa0fd630dbfd0715f5c9d406b4a583a7c9cf55d55e3b405d44b39f0940f69d97ee4b
ep_bytes: e816080000e974feffff8b4df464890d
timestamp: 2021-12-22 22:21:05

Version Info:

FileVersion: 1.0.0.5
LegalCopyright: 2020-2022 All rights reserved
Translation: 0x0409 0x04b0

Trojan.GenericRI.S26141407 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83088
FireEyeGeneric.mg.73726c7ad018c36e
CAT-QuickHealTrojan.GenericRI.S26141407
McAfeeGenericRXRF-YE!73726C7AD018
CylanceUnsafe
SangforTrojan.Win32.Agentb.gen
K7AntiVirusTrojan ( 005690671 )
AlibabaTrojan:Win32/Clipbanker.5147df37
K7GWTrojan ( 005690671 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ADUB
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderTrojan.GenericKDZ.83088
SUPERAntiSpywareTrojan.Agent/Gen-Razy
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10cfaf16
Ad-AwareTrojan.GenericKDZ.83088
SophosMal/Generic-S
EmsisoftTrojan.GenericKDZ.83088 (B)
GDataWin32.Trojan.PSE.1HTCX6D
JiangminTrojan.Agentb.ldq
AviraTR/Agent.mxixk
MicrosoftTrojan:Win32/Sabsik!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R460550
BitDefenderThetaGen:NN.ZexaF.34182.pu0@ayNKE9ki
ALYacTrojan.GenericKDZ.83088
MAXmalware (ai score=80)
VBA32Trojan.Agentb
MalwarebytesMalware.AI.4035918426
RisingTrojan.Agent!8.B1E (CLOUD)
FortinetW32/Redcap.ROQJ!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.GenericRI.S26141407?

Trojan.GenericRI.S26141407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment