Trojan

Trojan.IgenericIH.S20143317 malicious file

Malware Removal

The Trojan.IgenericIH.S20143317 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.IgenericIH.S20143317 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.IgenericIH.S20143317?


File Info:

name: 6E3C1F35D6BE0AF6AE13.mlw
path: /opt/CAPEv2/storage/binaries/0e1f57d5b91e6862c77b863ed066b25998b9ab421585370557cf38e1ecfa4ffb
crc32: BE15B49F
md5: 6e3c1f35d6be0af6ae13ab2728cbc19a
sha1: a31f35ee3a712c7277c1025c555ebc442ef712cf
sha256: 0e1f57d5b91e6862c77b863ed066b25998b9ab421585370557cf38e1ecfa4ffb
sha512: ee36286ffc6e19acc127cc255ea577fc9348867ebee08e62e31182e0227a7307e9cfddd3b29b7fc5f4addac9fbf396a5519abd058fb83b3e675116d54324e7ad
ssdeep: 3072:3/K76L8oMtlMaGxrOLrWtOD+RM391dILv3eg3D8ACB98jOSi:3/K76L8oM1GxrOfZ68+v9DbjOS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1451412375B712A48CA514CB0EE6E5134DE44FD047A5AAAC74D44BEA2BD7E3C0AB1370D
sha3_384: 18ae8c9c6daff5aab92fa333aa9646ec2631f87f1969c46a66a81f39883e4cb4735942bf0cc21175086af185b03f01e7
ep_bytes: 60be00c043008dbe0050fcff57eb0b90
timestamp: 2014-07-18 11:29:05

Version Info:

CompanyName: GGS
FileDescription: BS.ru game
FileVersion: 1,0,687,ed19cdefc5f772286b6cfacff1f8b2ac2b70394b
InternalName: BS.ru
LegalCopyright: Copyright(c) 2010 - 2013
OriginalFilename: bs.exe
ProductName: BS.ru game
ProductVersion: 1,0,687,ed19cdefc5f772286b6cfacff1f8b2ac2b70394b
Translation: 0x0419 0x04b0

Trojan.IgenericIH.S20143317 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.6e3c1f35d6be0af6
CAT-QuickHealTrojan.IgenericIH.S20143317
SkyhighArtemis
McAfeeArtemis!6E3C1F35D6BE
Cylanceunsafe
ZillyaDownloader.Helper.Win32.118
SangforTrojan.Win32.Syncopate.Vlow
CrowdStrikewin/grayware_confidence_100% (W)
K7GWUnwanted-Program ( 0053edc31 )
K7AntiVirusUnwanted-Program ( 0053edc31 )
VirITPUP.Win32.Syncopate.A
ESET-NOD32a variant of Win32/Syncopate.C potentially unsafe
APEXMalicious
ClamAVWin.Malware.Generic-9853656-0
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Malware-gen
EmsisoftApplication.Downloader (A)
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.SuspectCRC
JiangminTrojanDownloader.Generic.aiis
WebrootW32.Trojan.Gen
GoogleDetected
VaristW32/Agent.TE.gen!Eldorado
Antiy-AVLRiskWare/Win32.Syncopate.c
XcitiumTrojWare.Win32.Agent.KDV@4x3daa
CynetMalicious (score: 100)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesGeneric.Malware.AI.DDS
YandexTrojan.GenAsa!7QARWxwyUNU
SentinelOneStatic AI – Suspicious PE
MaxSecureDownloader.not-a-virus.WIN32.Downloader.Generic_193486
FortinetRiskware/Syncopate
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan.IgenericIH.S20143317?

Trojan.IgenericIH.S20143317 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment