Malware

About “Win32:GenMaliciousA-TXU [Trj]” infection

Malware Removal

The Win32:GenMaliciousA-TXU [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMaliciousA-TXU [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Creates a hidden or system file

How to determine Win32:GenMaliciousA-TXU [Trj]?


File Info:

name: 0E07502499F348ED4A85.mlw
path: /opt/CAPEv2/storage/binaries/4cd9b5b6186c6cc332f7e07e67357492c14b2a81c6817ac36f4591fc2aadc429
crc32: 34FA7AE9
md5: 0e07502499f348ed4a8598c53cae0bf5
sha1: 09efd9e332f7cf89550d913a82b1577158f7006a
sha256: 4cd9b5b6186c6cc332f7e07e67357492c14b2a81c6817ac36f4591fc2aadc429
sha512: 17c81a1dbfa2655634040aa460767feaeb8b1462c77a3a7942f91f1d8478a8eb1aac640cccbd45301acd29848b89b4a71f9c428669f53d953b33f6e6855fcff7
ssdeep: 98304:9WJk5c+Hv4DorLRz71KbVaGNtMPBOJyClUUeIDNN36J3mT79hsILyr5HsmSzjL:9gcDu4BOJyzUXNN3Y3mTxhyRof
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B826CF227682C026C5231A314E1CEBED6A7EBE606F36529771C07F2F3EB16D15D24B52
sha3_384: 5c2bd2aec0126457cf6b827aa6c6565560d9b160a26063aa2b98bf80b777be1544267cfc7b908fa60943172c09581d43
ep_bytes: 60c644240c6ec744241cb9b672009cc7
timestamp: 2016-01-07 05:38:59

Version Info:

Translation: 0x0412 0x03a8

Win32:GenMaliciousA-TXU [Trj] also known as:

LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.0e07502499f348ed
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.332f7c
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Black.dzqaqm
AvastWin32:GenMaliciousA-TXU [Trj]
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.moderate.ml.score
SophosMal/VMProtBad-A
GoogleDetected
AviraTR/Black.Gen2
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!0E07502499F3
VBA32BScope.Trojan.Dynamer
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Win32.Generic.19884691 (C64:YzY0Ohs/7MLGpXwK)
YandexTrojan.GenAsa!pvjpZGEa7Yc
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZexaF.34592.@NW@ay3YyfiH
AVGWin32:GenMaliciousA-TXU [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32:GenMaliciousA-TXU [Trj]?

Win32:GenMaliciousA-TXU [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment