Trojan

Trojan:Win32/Propagate!mclg removal

Malware Removal

The Trojan:Win32/Propagate!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Propagate!mclg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

oldd.webtm.ru
www.bing.com
iplogger.org
ipinfo.io
www.listincode.com
ocsp.digicert.com
statuse.digitalcertvalidation.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
google.vrthcobj.com
ip-api.com

How to determine Trojan:Win32/Propagate!mclg?


File Info:

crc32: 45C96E26
md5: 15fd29325e11aa1777bdde1e09829784
name: 15FD29325E11AA1777BDDE1E09829784.mlw
sha1: 276c234a544054072593fb3b87e2a37f81e4f3c5
sha256: 2ec6c6341ff83005a6515d942976d2092549312d419a29e59d0efb15d65749bf
sha512: 53a1d60c2e6b679b89effb81da0cc0bce4d26644d5ce190258ce6d9821802bb8aa1f349a61567d4806f19acbcdb34e6a3cb66d72a4a8169223165c7396eda02d
ssdeep: 98304:UbvDpNv9xyFximcWtxL4iZ1XxDLv6BFe6:UoxHcCLn3pLiBFe6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Propagate!mclg also known as:

K7AntiVirusTrojan-Downloader ( 0057dba01 )
LionicTrojan.Win32.Makop.trQA
Elasticmalicious (high confidence)
ClamAVWin.Malware.Clipbanker-9873068-0
CAT-QuickHealTrojanpws.Racealer
ALYacTrojan.GenericKDZ.76432
CylanceUnsafe
AlibabaTrojanPSW:Win32/Socelars.ce05948c
K7GWTrojan-Downloader ( 0057dba01 )
Cybereasonmalicious.25e11a
BitDefenderThetaGen:NN.ZemsilF.34058.ku0@aSEe@Vo
CyrenW32/Trojan.UBDH-2162
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Racealer.llx
BitDefenderTrojan.GenericKD.46677498
NANO-AntivirusTrojan.Win32.Inject4.ixgvgd
MicroWorld-eScanTrojan.GenericKD.46677498
SophosMal/Generic-S
ComodoMalware@#1bi7s367k5ugy
DrWebTrojan.DownLoader40.43962
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGG21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.15fd29325e11aa17
EmsisoftTrojan.GenericKD.46677498 (B)
SentinelOneStatic AI – Malicious SFX
AviraTR/AD.DisSteal.quwkd
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.340C0ED
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Propagate!mclg
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D2C83DFA
GDataWin32.Trojan.BSE.1353AB1
AhnLab-V3Trojan/Win.Generic.C4585796
McAfeeArtemis!15FD29325E11
MAXmalware (ai score=88)
VBA32TrojanPSW.Racealer
MalwarebytesMalware.AI.2508788491
PandaTrj/CI.A
RisingMalware.Obscure!1.A3BB (CLASSIC:f3tPw873R7oc8j0BW9xg5Q)
YandexTrojan.Agent!fECXbpTI758
FortinetW32/Autoit.PDT!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Raccoon.HwYDueAA

How to remove Trojan:Win32/Propagate!mclg?

Trojan:Win32/Propagate!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment