Trojan

Trojan.Win32.Reconyc.ojta removal

Malware Removal

The Trojan.Win32.Reconyc.ojta is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Reconyc.ojta virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Harvests cookies for information gathering

How to determine Trojan.Win32.Reconyc.ojta?


File Info:

name: 4581F2E711C3911FA946.mlw
path: /opt/CAPEv2/storage/binaries/f9171e0d7a68437b483ab1e8679720a80b9e3d2dc77cdd67c2a0b7531de8eff6
crc32: 2AC7F965
md5: 4581f2e711c3911fa946c4138c490403
sha1: 03e3f27ed6a5d5f37c174576a6150baea9f2970e
sha256: f9171e0d7a68437b483ab1e8679720a80b9e3d2dc77cdd67c2a0b7531de8eff6
sha512: 2cff051e9b53da6737d8d854bb35b08488ad6b1b621072bf88742f8079f2f780823f69f02a4174760dfd633ba16a375612dac417224f2afa80cbc8d881749a75
ssdeep: 6144:NPeHr7/4LtQsFL9myaZ0Utp+PHp1OcnPIaRboSdG:NPeHr7/4WsFL9mXwPHNgaFoS4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF34D11375D3C4B3E26204318AD50BF99FFDDA7339B32A7FEB508AA94CB05804A164B5
sha3_384: eea4f7221c6db28991ecefee044167f4164cd60e7ca24ad3fbe25288a9941ecf17fbd413c8835ad8ccb0ba57a439974d
ep_bytes: 558bec6aff6810814100684895400064
timestamp: 2021-12-04 12:56:53

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Win32.Reconyc.ojta also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.4581f2e711c3911f
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
Cybereasonmalicious.711c39
BitDefenderThetaGen:NN.ZexaF.34084.oq0@aeIA6dkb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Tiny.NQG
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Reconyc.ojta
BitDefenderGen:Trojan.Malware.oq0@aeIA6dkb
MicroWorld-eScanGen:Trojan.Malware.oq0@aeIA6dkb
AvastFileRepMalware
Ad-AwareGen:Trojan.Malware.oq0@aeIA6dkb
EmsisoftGen:Trojan.Malware.oq0@aeIA6dkb (B)
DrWebTrojan.DownLoader44.11956
McAfee-GW-EditionBehavesLike.Win32.StartPage.dc
SophosMal/Generic-S
APEXMalicious
GDataWin32.Application.PUPStudio.A
MaxSecureDropper.Dinwod.frindll
AviraHEUR/AGEN.1133732
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
SentinelOneStatic AI – Malicious PE
ALYacGen:Trojan.Malware.oq0@aeIA6dkb
MalwarebytesPUP.Optional.ChinAd
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazr3nCHIPKw2qHh4rZbvymSs)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Win32.Reconyc.ojta?

Trojan.Win32.Reconyc.ojta removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment