Trojan

About “Trojan:Win32/Picrosia.C” infection

Malware Removal

The Trojan:Win32/Picrosia.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Picrosia.C virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

upload101.net
upload999.net

How to determine Trojan:Win32/Picrosia.C?


File Info:

crc32: 109A831F
md5: 5bbb5604bc0f656545dfcbb09820d61a
name: 5BBB5604BC0F656545DFCBB09820D61A.mlw
sha1: a4cac28e41ad799abc1213689230985811cf0b76
sha256: 54e5f4ecd18c6a18a6f25be6b7a392cbbd5bc107b868d8a078bf3e3fa701e453
sha512: 4296a3ad0a930bb7a62ca11fe4cb77776788d030a32970ff5c3e5ffbd4682e647baf2e9b7b8dbc09b668efd5b08e5e8a3cca5cecc16aca23ea2aad78fdf930ba
ssdeep: 49152:5YkAhDAlGsxRdZ3DuYLsG86sfp6lF0S1YfNGGGGGGGGGG2:YhDAEsxt3yM98Rf4F0S1Y1GGGGGGGGG
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan:Win32/Picrosia.C also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3e61 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Banker1.22853
ALYacGeneric.Ransom.CloudSword.AC841EF1
CylanceUnsafe
ZillyaTrojan.Generic.Win32.38704
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Picrosia.2ef41248
K7GWTrojan ( 0055e3e61 )
Cybereasonmalicious.4bc0f6
ESET-NOD32Win32/Delf.AXW
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.CloudSword.AC841EF1
NANO-AntivirusTrojan.Win32.Agent.efkcfw
MicroWorld-eScanGeneric.Ransom.CloudSword.AC841EF1
TencentWin32.Trojan.Generic.Szcd
Ad-AwareGeneric.Ransom.CloudSword.AC841EF1
SophosMal/Generic-S
ComodoMalware@#oemfv055rau5
BitDefenderThetaGen:NN.ZelphiF.34050.KnKfaiI6NBhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.DlHelper.tc
EmsisoftGeneric.Ransom.CloudSword.AC841EF1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.aehqz
WebrootW32.Gen.BT
AviraTR/Agent.twpf
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitGeneric.Ransom.CloudSword.AC841EF1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Picrosia.C
McAfeeArtemis!5BBB5604BC0F
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
YandexTrojan.Agent!jgJ71yAK2yQ
IkarusTrojan.Win32.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AXW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Micropsia.HgIASRMA

How to remove Trojan:Win32/Picrosia.C?

Trojan:Win32/Picrosia.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment