Trojan

Trojan.Generic.23210755 malicious file

Malware Removal

The Trojan.Generic.23210755 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.23210755 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Connects to an IRC server, possibly part of a botnet

Related domains:

hao.zhmeihua.com
dl.lmrjxz.com

How to determine Trojan.Generic.23210755?


File Info:

crc32: 11D95DD4
md5: 205a65db07721dd94a291c6045c34999
name: 205A65DB07721DD94A291C6045C34999.mlw
sha1: 3b7d7b94c2a84396c2ece4372270c65613a03310
sha256: 1e116e41850a46bb0003bbe6b43b95c724c0ab643cac26b99f6103037ad48341
sha512: 2898ac06c1304504f1032231301bdda903a054ff617aebc54877cb0cb6aeb0687224e0c7a8ab0bb75c3ded1b142e44822e76965fc9023ed822355a4bc2a59a59
ssdeep: 12288:+oN4/vMeKMxkEIm+zkPzyfCal/emL4GoOfTO1qLal:+b/vMe3kXmtO6cWmLd1i1ial
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Generic.23210755 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.Generic.lQvU
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.61774
CynetMalicious (score: 100)
ALYacTrojan.Generic.23210755
CylanceUnsafe
AlibabaTrojanPSW:Win32/QQpass.bc49477e
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.b07721
CyrenW32/S-e41fbf72!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.Generic.23210755
NANO-AntivirusTrojan.Win32.FlyStudio.fkmnlk
MicroWorld-eScanTrojan.Generic.23210755
Ad-AwareTrojan.Generic.23210755
SophosGeneric ML PUA (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34266.7qW@aGFQlOnb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.205a65db07721dd9
EmsisoftTrojan.Generic.23210755 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2990EE1
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1622B03
GDataWin32.Trojan.PSE.12FI8JT
Acronissuspicious
McAfeeGenericRXBW-XR!205A65DB0772
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.96 (RDMK:3iqAP8iLpTPdYiTc1eThqA)
IkarusTrojan-PSW.QQpass
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/GenericRXBW
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Generic.23210755?

Trojan.Generic.23210755 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment