Malware

Win32:GenMalicious-ICH [Trj] removal guide

Malware Removal

The Win32:GenMalicious-ICH [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMalicious-ICH [Trj] virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ninauwur.duckdns.org
stolensky.duckdns.org

How to determine Win32:GenMalicious-ICH [Trj]?


File Info:

crc32: D7BE0A7E
md5: c1515c8ad9887d0c7b38d048e7e8d76e
name: C1515C8AD9887D0C7B38D048E7E8D76E.mlw
sha1: 50ef77d312618883cffc85beb66f4a26d09d7688
sha256: 2bab5546123fcf539b4498f86aa979ca9db1408384961fef84a82d87a1a1e6b5
sha512: 51aff5f1eb82a6a9ae65f22e32a4cf4ad4dabceaac7fc40f25833c3415d9d0b737aa39f1d5a8395458f1944a75a312972dc7627392f520d9712ba04ea472f353
ssdeep: 6144:qYLtU7Ixhnhz5aqHCIxmLrDTw6UPuc4dj8+gPevsNiv1:xsI3lTiQG38C1cevHd
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Win32:GenMalicious-ICH [Trj] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Tordev.8
MicroWorld-eScanGenPack:Trojan.Inject.AUZ
FireEyeGeneric.mg.c1515c8ad9887d0c
Qihoo-360HEUR/QVM19.1.3FBB.Malware.Gen
McAfeeGeneric BackDoor.yl
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGenPack:Trojan.Inject.AUZ
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.ad9887
TrendMicroBKDR_FYNLOS.SMM
BitDefenderThetaAI:Packer.EEC9D7D31C
CyrenW32/S-777a0fdc!Eldorado
SymantecBackdoor.Breut!gm
ZonerTrojan.Win32.33864
TrendMicro-HouseCallBKDR_FYNLOS.SMM
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.aagt
NANO-AntivirusTrojan.Win32.Delf.vudbk
RisingTrojan.Generic@ML.100 (RDML:3gATA1hMd8Z41yGkXYv0Hg)
Ad-AwareGenPack:Trojan.Inject.AUZ
EmsisoftTrojan.Fynloski (A)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Backdoor.Agent.l
InvinceaML/PE-A + Mal/Fynloski-C
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
SentinelOneStatic AI – Malicious PE
SophosMal/Fynloski-C
IkarusTrojan.Win32.Jorik
JiangminTrojan/Generic.afkli
AviraBDS/Backdoor.Gen
MicrosoftBackdoor:Win32/Fynloski
GridinsoftTrojan.Win32.FlyStudio.vl!i
ArcabitGenPack:Trojan.Inject.AUZ
SUPERAntiSpywareBackdoor.Fynloski/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.aagt
GDataGenPack:Trojan.Inject.AUZ
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/FCN.140610.X1341
Acronissuspicious
VBA32Backdoor.Tordev
ALYacGenPack:Trojan.Inject.AUZ
MAXmalware (ai score=84)
MalwarebytesBackdoor.DarkComet
APEXMalicious
ESET-NOD32a variant of Win32/Fynloski.AS
eGambitUnsafe.AI_Score_94%
FortinetW32/Generic.AC.1644!tr
AVGWin32:GenMalicious-ICH [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureBackdoor.W32.DarkKomet.aagr

How to remove Win32:GenMalicious-ICH [Trj]?

Win32:GenMalicious-ICH [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment