Trojan

About “Trojan.GenericRI.S7106973” infection

Malware Removal

The Trojan.GenericRI.S7106973 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S7106973 virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Trojan.GenericRI.S7106973?


File Info:

crc32: 01442032
md5: 964ff7fb2247c449172e5d294f240bdc
name: 12-146-6-106.exe
sha1: 5fc88d065795c089f8033bc3bf84c54b756fc715
sha256: 9bacbcf140646654b2ce8c9578027fb646d77aefdc7254769020673b1bf57927
sha512: a9b0ae43c864d6165d8982f865af933d5615ff8b5b6fdc93be8f7843a1bd0d5f5925100e165a74323a2a595946d47b3b57a70090f7427309963c797e0ae83418
ssdeep: 1536:tvwIMUkn5lRjATpx6GWT4T/aj+F203TuGuf+/Z0Y:RJknVKucT/u+R3Tubf80Y
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.GenericRI.S7106973 also known as:

MicroWorld-eScanGen:Variant.Kazy.67252
FireEyeGeneric.mg.964ff7fb2247c449
CAT-QuickHealTrojan.GenericRI.S7106973
McAfeeDialer-RAS.a.gen
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.bsc (vs)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Kazy.67252
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b2247c
TrendMicroDIAL_RAS.HE
F-ProtW32/Webdialer.gen!GSA
TotalDefenseWin32/DDialer_i
APEXMalicious
AvastWin32:Dialer-ACP [Trj]
ClamAVWin.Trojan.Dialer-202
GDataGen:Variant.Kazy.67252
KasperskyTrojan.Win32.Scar.fmke
NANO-AntivirusTrojan.Win32.Scar.exuuur
ViRobotTrojan.Win32.A.Scar.62513[UPX]
AegisLabRiskware.Win32.Generic.l0jn
TencentMalware.Win32.Gencirc.10b3ae33
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Kazy.67252 (B)
ComodoApplicUnsaf.Win32.Dialer.Generic@jux8x
F-SecureDialer.DIAL/000293
DrWebDialer.Online.2
ZillyaTrojan.Scar.Win32.72351
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dialer.qc
SophosDial/190-A
IkarusDialer
CyrenW32/Webdialer.gen!GSA
JiangminTrojan/Generic.bfcl
AviraDIAL/000293
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Scar
MicrosoftTrojan:Win32/Detplock
ArcabitTrojan.Kazy.D106B4
ZoneAlarmTrojan.Win32.Scar.fmke
AhnLab-V3Adware/Win32.Dialer.R21773
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34090.dmGfaWSoEXq
ALYacGen:Variant.Kazy.67252
VBA32Trojan.Scar
PandaDialer.Gen
ESET-NOD32a variant of Win32/Dialer.0190-Dialers
TrendMicro-HouseCallDIAL_RAS.HE
RisingHackTool.PornDialer!1.6613 (CLASSIC)
YandexDialer.eConnect.Gen
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Scar.FMKE!tr
Ad-AwareGen:Variant.Kazy.67252
AVGWin32:Dialer-ACP [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM11.1.5453.Malware.Gen

How to remove Trojan.GenericRI.S7106973?

Trojan.GenericRI.S7106973 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment