Trojan

Trojan:Win32/Sluegot.A information

Malware Removal

The Trojan:Win32/Sluegot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sluegot.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Sluegot.A?


File Info:

name: 4CE22CEE6ABCB37DB757.mlw
path: /opt/CAPEv2/storage/binaries/e542f90b57ea60f788b5a17b59696331c157e3c508abcc99fbdf0956a624bf79
crc32: B54DD912
md5: 4ce22cee6abcb37db757e3fd60970090
sha1: 407470976e31f468e3322365aaf7385633a5ae16
sha256: e542f90b57ea60f788b5a17b59696331c157e3c508abcc99fbdf0956a624bf79
sha512: 42caae97f66f45e316e5d374375be319ee5358ef08a5ad1689341dee824579e82b3119bcd3165686855a9e00a40f28eb81d6c89e983a69e82633830f4d183f28
ssdeep: 192:6dWA91DZQiBWUxCnrNvSw0ZiJNX3YJDUjJFqByUeMZ+K1+64XXvXXaEeSRfwE1on:6/9DQidyYJZir3YJ+0MKjEei/1hcXR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116624CC7F8558B71CB314EB03F64A9266EE694B53531A0ABFB444A098C3D182A53F71E
sha3_384: 268be3c5260e384e1975c3d2efb43c476dbaa7b8093b5e87b42048aa6ef76ca9ac5ab495686dec5060e781250a37f7ef
ep_bytes: 558bec6aff6878414000687835400064
timestamp: 2010-09-28 08:09:41

Version Info:

0: [No Data]

Trojan:Win32/Sluegot.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Scar.trIU
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader5.8015
MicroWorld-eScanGeneric.Malware.SF!dld!.0EE141EF
FireEyeGeneric.mg.4ce22cee6abcb37d
McAfeeGenericRXCC-HK!4CE22CEE6ABC
MalwarebytesMalware.AI.2497592198
ZillyaTrojan.Scar.Win32.50865
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Sluegot.351e060d
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
ArcabitGeneric.Malware.SF!dld!.0EE141EF
BitDefenderThetaAI:Packer.9E11A0F01E
VirITTrojan.Win32.Generic.BHZP
CyrenW32/Trojan-Sml-IWW!Eldorado
SymantecTrojan.Downbot.B
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.QIM
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0CGP22
Paloaltogeneric.ml
ClamAVWin.Trojan.Merong-1
KasperskyTrojan.Win32.Scar.dcrm
BitDefenderGeneric.Malware.SF!dld!.0EE141EF
NANO-AntivirusTrojan.Win32.Scar.chxtv
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10d06996
Ad-AwareGeneric.Malware.SF!dld!.0EE141EF
EmsisoftGeneric.Malware.SF!dld!.0EE141EF (B)
ComodoMalware@#19d6jbp4g3ukf
VIPREGeneric.Malware.SF!dld!.0EE141EF
TrendMicroTROJ_GEN.R002C0CGP22
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lm
SophosTroj/DwnLdr-JEA
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bifm
WebrootW32.Trojan.Scar
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.103
KingsoftWin32.Troj.Scar.dc.(kcloud)
MicrosoftTrojan:Win32/Sluegot.A
ViRobotTrojan.Win32.A.Scar.15360
GDataGeneric.Malware.SF!dld!.0EE141EF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R81257
VBA32Trojan.Scar
ALYacGeneric.Malware.SF!dld!.0EE141EF
TACHYONTrojan/W32.Scar.15360.P
CylanceUnsafe
RisingTrojan.Generic@AI.100 (RDML:mBVIiVc/qIhtDipIaifgVA)
YandexTrojan.GenAsa!lNwICMlZnd4
IkarusVirus.Win32.Malware
FortinetW32/Agent.QIM!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.e6abcb
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Sluegot.A?

Trojan:Win32/Sluegot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment