Trojan

How to remove “Trojan.Generic.22941930”?

Malware Removal

The Trojan.Generic.22941930 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.22941930 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Attempts to connect to a dead IP:Port (2616 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • EternalBlue behavior

How to determine Trojan.Generic.22941930?


File Info:

crc32: 939B4450
md5: 43cd05afde6a69ba3de185f53c4149cb
name: scanip.exe
sha1: 656b097dc635af32736b6e33473e2871b35548c0
sha256: 51dadbbd3b0b3f200fcb3d9d8b1e9f58aceec0511ae0253d3076e78c02fbcaac
sha512: c27737291b39da89fbd94d39747f0de5075e968da6b689bb174a814a013b506fe89f2d87829c9b1d2f8cca7b0cf2b51c721182941ada88ba4b71d0d8daa497b2
ssdeep: 196608:kUwmeLirm1FHeMoUZbYowem4LKb2lBgip6YDC:kUwmeNX+MndwemmKbGdXC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Generic.22941930 also known as:

CMCBackdoor.Win32.Agent!O
CAT-QuickHealTrojan.Fuerboos
VIPRETrojan.Win32.Generic!BT
K7GWTrojan-Downloader ( 0052aaab1 )
K7AntiVirusTrojan-Downloader ( 0052aaab1 )
TrendMicroTROJ_GEN.R002C0DEE18
NANO-AntivirusTrojan.Win64.Blouiroet.fcdogv
CyrenW64/Trojan.QNKO-3535
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0DEE18
AvastWin64:Malware-gen
GDataWin32.Trojan.Agent.1XMH8E
KasperskyHEUR:Trojan.Win32.Blouiroet.gen
BitDefenderTrojan.Generic.22941930
ViRobotTrojan.Win32.Z.Shadowbrokers.7078275
AegisLabTroj.W32.Blouiroet!c
RisingTrojan.Eqtonex!8.E3CD (KTSE)
SophosMal/Generic-S
Comodo.UnclassifiedMalware
F-SecureTrojan.Generic.22941930
DrWebBackDoor.Spy.3364
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.vc
EmsisoftTrojan.Generic.22941930 (B)
SentinelOnestatic engine – malicious
F-ProtW32/Downloader-Web-based!Maximu
WebrootW32.Trojan.ShadowBrokers
AviraTR/Dldr.Agent.zomzh
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D4A814A
ZoneAlarmHEUR:Trojan.Win32.Blouiroet.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Blouiroet.C2519914
McAfeeArtemis!43CD05AFDE6A
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=99)
VBA32Trojan.Blouiroet
PandaTrj/CI.A
ESET-NOD32a variant of Win64/TrojanDownloader.Agent.BX
TencentWin32.Trojan.Shadowbrokers.Pdmr
YandexTrojan.Blouiroet!
IkarusTrojan-Downloader.Win64.Agent
FortinetW32/Blouiroet.AC!tr
AVGWin64:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.b0a

How to remove Trojan.Generic.22941930?

Trojan.Generic.22941930 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment