Trojan

Trojan.Generic.23030758 information

Malware Removal

The Trojan.Generic.23030758 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23030758 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.23030758?


File Info:

name: 9FB8B6188AB06C7A4551.mlw
path: /opt/CAPEv2/storage/binaries/e18e2fdd6cc67ac4205f464cad62d6e18e5c4049bbd09a4d6731460700e23e82
crc32: 32ED653D
md5: 9fb8b6188ab06c7a4551085deeaad983
sha1: 08b3c580ec2d07f447bb9333e316616d70c77a9a
sha256: e18e2fdd6cc67ac4205f464cad62d6e18e5c4049bbd09a4d6731460700e23e82
sha512: a7ee9f36fc2eff01d6f1f9b4e0116a9af4d87458740427cf9035c96766e31df6129926a647f263d538308d0c1135e0812a0e14f19189066bdee3a1393256f8d8
ssdeep: 768:lXA/H/2tqjyn1LheerkRWgOh3YE5SK133N/mtv3m1CfnbcuyD7UHOm:lw/Hut1n1LqRSh3YEMmHN/mtvW4fnouV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181F2E16AD0C4872ED0BE01B71BEB61170A10A2281D511F27F4DD7B7B0F87D485C9C7AA
sha3_384: 1bfaead890cfcc8c3973edc665e61ae82da0f72d9629426df75ab9ccd2c01c52359aef71ed592e3f397f3ab27ebfc3d6
ep_bytes: 60be15f040008dbeeb1fffff5789e58d
timestamp: 2016-05-27 14:05:04

Version Info:

FileVersion: 1,3,0,0
ProductVersion: 1.3.0.0
Translation: 0x0000 0x04e4

Trojan.Generic.23030758 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
CynetMalicious (score: 100)
ALYacTrojan.Generic.23030758
AlibabaTrojan:Win32/Generic.1d842764
Cybereasonmalicious.88ab06
CyrenW32/Agent.BJD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.Generic.23030758
NANO-AntivirusTrojan.Win32.Agent.eguykl
MicroWorld-eScanTrojan.Generic.23030758
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.23030758
SophosGeneric ML PUA (PUA)
DrWebTrojan.MulDrop8.37976
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.9fb8b6188ab06c7a
EmsisoftTrojan.Generic.23030758 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.23030758
JiangminPSWTool.Python.l
Antiy-AVLTrojan/Generic.ASMalwS.18F9E05
ArcabitTrojan.Generic.D15F6BE6
MicrosoftTrojan:Win32/Occamy.CE1
AhnLab-V3Malware/Win32.Generic.C2751065
Acronissuspicious
McAfeeArtemis!9FB8B6188AB0
VBA32Trojan.Downloader
MalwarebytesMalware.AI.1982466076
TrendMicro-HouseCallTROJ_GEN.R002H0CJ721
YandexTrojan.Agent!VmQgQtmMvXA
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.23030758?

Trojan.Generic.23030758 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment