Trojan

How to remove “Dropped:Trojan.Generic.22908104”?

Malware Removal

The Dropped:Trojan.Generic.22908104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Generic.22908104 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • ‘Google Drive’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
xred.mooo.com
a.tomx.xyz
freedns.afraid.org
ocsp.pki.goog

How to determine Dropped:Trojan.Generic.22908104?


File Info:

crc32: 9BA66F9B
md5: c11843d1005e7460a71f3ada96db5994
name: tool.exe
sha1: 25798e3b17d87c3b3f6b8b1777d4944aca24c820
sha256: 81253f77b89552d5edb8434530f54f4505030def6e7c134e3b06371b8a5561a6
sha512: 1e42f6764b6cd1885a0506b0731866f47ea801e4e445684991108de48dcdb9088bbf37cde8d303eb14e807c9a26f65501be9b8adf30d5732eeffd08383f263ca
ssdeep: 12288:mMSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9zYj:mnsJ39LyjbJkQFMhmC+6GD90
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Dropped:Trojan.Generic.22908104 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanDropped:Trojan.Generic.22908104
FireEyeGeneric.mg.c11843d1005e7460
CAT-QuickHealW32.Delf.NB4
ALYacDropped:Trojan.Generic.22908104
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
AegisLabTrojan.Win32.DarkKomet.tp6k
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Trojan.Generic.22908104
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1005e7
TrendMicroVirus.Win32.NAPWHICH.B
BitDefenderThetaAI:Packer.F5AF03D517
F-ProtPP97M/Script.gen
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
AvastWin32:Malware-gen
ClamAVWin.Malware.Delf-6899401-0
GDataDropped:Trojan.Generic.22908104
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaBackdoor:Win32/DarkKomet.e0f1f77a
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
APEXMalicious
RisingBackdoor.Agent!1.BF3D (CLOUD)
Ad-AwareDropped:Trojan.Generic.22908104
SophosGeneric PUA BI (PUA)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
DrWebTrojan.DownLoader22.9658
ZillyaTrojan.Delf.Win32.76144
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSOnlineGames.bh
Trapminesuspicious.low.ml.score
EmsisoftDropped:Trojan.Generic.22908104 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.ZTAB-6291
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Script.AGeneric
Endgamemalicious (high confidence)
ArcabitHEUR.VBA.Trojan.d
SUPERAntiSpywareAdware.FileTour/Variant
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
MicrosoftWorm:Win32/AutoRun.XXY!bit
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
McAfeeGenericRXCB-VC!C11843D1005E
VBA32BScope.Backdoor.DarkKomet
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ESET-NOD32Win32/Delf.NBX
TencentMalware.Win32.Gencirc.10b8ace3
YandexRiskware.BlackMoon!
IkarusTrojan-PWS.Win32.QQPass
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.NBX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Virus.Synaptics.A

How to remove Dropped:Trojan.Generic.22908104?

Dropped:Trojan.Generic.22908104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment