Trojan

Trojan.Genome.ah malicious file

Malware Removal

The Trojan.Genome.ah is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Genome.ah virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Genome.ah?


File Info:

name: 4A31AD8C2F516C835A19.mlw
path: /opt/CAPEv2/storage/binaries/1b2f7a496478f6f6ce1bcbfdcec6f3f716bfa1d1a2a6101dd9a41dac5ac02777
crc32: 0CCBEB97
md5: 4a31ad8c2f516c835a190d901b883a3e
sha1: cce7712d1bd8de995457a2f070152a237466d664
sha256: 1b2f7a496478f6f6ce1bcbfdcec6f3f716bfa1d1a2a6101dd9a41dac5ac02777
sha512: 833d33afb8734b82935e54e40a09670115749f133d645823b4b17cd2928fa71b702038710bcf59a748fbd5ca142587a3176a64efc1fb2e43a71716a6b3f9db53
ssdeep: 6144:coI7NHEoSckSoKHluVsAtt72p1ZCp67DkJf2rwVErYOG:4KoNbl0sc723ZCpKDkJ2cKcOG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DA41252F5D0DCA9C7531A3011B2B362EBB2CB0BD163428BD7905F9FBA74987472E192
sha3_384: 612affedc45a9588e6fcfbb7ddc887c21222e599dbd0c3ab8eae876dbcb2037abfd2a1012173d6e2716f3c0e858eeee3
ep_bytes: 81ec7c01000053555633f65789742418
timestamp: 2004-01-23 23:39:42

Version Info:

0: [No Data]

Trojan.Genome.ah also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Graftor.8014
ALYacGen:Variant.Graftor.8014
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/SuspPack.121c2440
K7GWTrojan ( 003b1b581 )
K7AntiVirusTrojan ( 003b1b581 )
CyrenW32/SuspPack.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
NANO-AntivirusTrojan.Win32.Zlob.gxths
AvastWin32:TrojanX-gen [Trj]
ComodoBackdoor.Win32.Popwin.~IT@pe303
McAfee-GW-EditionBehavesLike.Win32.Infected.gm
FireEyeGeneric.mg.4a31ad8c2f516c83
SophosGeneric PUA MM (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.ZB9C22
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
McAfeeRDN/Generic.rp
VBA32Trojan.Genome.ah
TrendMicro-HouseCallTROJ_GEN.R002H0CE622
RisingTrojan.Generic@AI.100 (RDMK:cmRtazoMooQ8cvDj0BpaOQFw7mce)
Ikarusnot-a-virus:Porn-Dialer.Win32.Generic
MaxSecureTrojan.W32.Packer.Upack0.3.9
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan.Genome.ah?

Trojan.Genome.ah removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment