Trojan

Trojan.Generic.30169468 information

Malware Removal

The Trojan.Generic.30169468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30169468 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Morocco)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Trojan.Generic.30169468?


File Info:

crc32: 8C766959
md5: 44623ee8789fa772b12cff0b5c99c312
name: 44623EE8789FA772B12CFF0B5C99C312.mlw
sha1: 975709516cad135e66c524970a7498626d673399
sha256: da1cc22610174ea023aa52f164e4afe7e2cb858fd0a838dbcb07a079fb60bd0c
sha512: aee9d9f136a943ad1012ff613d87a12f195c68bf08fd6cd3bedebbd94843248d60efacb41bf54658d7aee55b9b7bd61f6dc99024925b16050db361f0c65bf1d1
ssdeep: 12288:hNTwjs65b81E9F7AtLWWQYj38VB415WSEbjToA2XXgOfbRFA2:wPR81E95hYj38z49A0U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Generic.30169468 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00581f861 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Generic-9893540-0
CAT-QuickHealRansom.Stop.Z5
McAfeePacked-GDT!44623EE8789F
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/StopCrypt.1017
K7GWTrojan ( 00581f861 )
Cybereasonmalicious.16cad1
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMMS
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.DiskWriter.gen
BitDefenderTrojan.Generic.30169468
MicroWorld-eScanTrojan.Generic.30169468
Ad-AwareTrojan.Generic.30169468
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34170.KuW@aGxZaXdO
TrendMicroRansom_StopCrypt.R011C0DIM21
McAfee-GW-EditionBehavesLike.Win32.Corrupt.hc
FireEyeGeneric.mg.44623ee8789fa772
EmsisoftTrojan.Generic.30169468 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt.MFK!MTB
ZoneAlarmHEUR:Trojan.Win32.DiskWriter.gen
GDataWin32.Trojan.BSE.XGXYJ9
AhnLab-V3Trojan/Win.MalPE.R441743
Acronissuspicious
VBA32Malware-Cryptor.Azorult.gen
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_StopCrypt.R011C0DIM21
RisingTrojan.Kryptik!1.D975 (CLASSIC)
YandexTrojan.DiskWriter!gxj3IHeRXGE
IkarusTrojan-Spy.Agent
FortinetW32/DiskWriter.HMMS!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Trojan.Generic.30169468?

Trojan.Generic.30169468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment