Trojan

Trojan.GenericRI.S28495279 information

Malware Removal

The Trojan.GenericRI.S28495279 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S28495279 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.GenericRI.S28495279?


File Info:

name: 742F05CD0F8875304EAA.mlw
path: /opt/CAPEv2/storage/binaries/d64ee97d3c2876162e85e2c800533ede23b74be07509f24545df0c22db5b2a00
crc32: 83252D3C
md5: 742f05cd0f8875304eaa43b878cf07e4
sha1: f6cebcfaee70bc57058268c1588a338db2234cc6
sha256: d64ee97d3c2876162e85e2c800533ede23b74be07509f24545df0c22db5b2a00
sha512: d980e000e28ab87dbeb4e189dbddd5cc24beaac303ebaf81854cbdaf3e4370ae05d70cf4c8fc2497058ebbd5c95a11c8b823a5e904daabca12c5168c129e50de
ssdeep: 12288:1srjeS3UVprYfELtx6uz6s3Q4KsfZVutS6d:6HeaUVxYVuzB3hZM0a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165A4B011B6D2C072D97255340D39EB26DEFCF920293586B7B3D60D99EE30180A72A7B7
sha3_384: fbe3931e4e782dd20ab10b8cceabfe4f9fc6cab83828f5ebc70affa7cb84005fec83e19ed44e27830e46ffa570657fc0
ep_bytes: e859040000e98efeffff558bec81ec24
timestamp: 2022-05-20 16:04:59

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.546
Translation: 0x0409 0x04b0

Trojan.GenericRI.S28495279 also known as:

BkavW32.YggiLykeyW.Trojan
LionicTrojan.Win32.Generic.4!c
ElasticWindows.Trojan.Remcos
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericRI.S28495279
McAfeeGenericRXRU-NF!742F05CD0F88
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053ac2c1 )
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.aee70b
BaiduWin32.Trojan.Kryptik.awm
VirITTrojan.Win32.Genus.LGX
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Rescoms.B
APEXMalicious
ClamAVWin.Trojan.Remcos-9841897-0
AlibabaTrojanSpy:Win32/Remcos.028d0447
NANO-AntivirusTrojan.Win32.Rescoms.jozrho
MicroWorld-eScanGeneric.Dacic.A9349469.A.810DCF60
TencentMalware.Win32.Gencirc.10bda39f
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.DownLoader44.61502
ZillyaTrojan.Rescoms.Win32.915
SophosTroj/Remcos-DI
IkarusTrojan-Spy.Remcos
JiangminTrojan.Generic.hhyly
VaristW32/Trojan.HDAE-4343
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
MicrosoftTrojan:Win32/Remcos!ic
GoogleDetected
AhnLab-V3Trojan/Win.RemcosRAT.R494595
BitDefenderThetaGen:NN.ZexaF.36792.BC0@a40wATfi
DeepInstinctMALICIOUS
VBA32Trojan.Downloader
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
YandexTrojan.Agent!JqHzLzIkEzc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Remcos.A!tr
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.GenericRI.S28495279?

Trojan.GenericRI.S28495279 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment