Trojan

Trojan.Generic.30181956 removal guide

Malware Removal

The Trojan.Generic.30181956 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30181956 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Generic.30181956?


File Info:

crc32: ED8B04DE
md5: ef799b5261fd69b56c8b70a3d22d5120
name: EF799B5261FD69B56C8B70A3D22D5120.mlw
sha1: 65b43bfe8a5f2481d70b76ebd543b9f5b4baa0f6
sha256: 3c280f4b81ca4773f89dc4882c1c1e50ab1255e1975372109b37cf782974e96f
sha512: 02bf6df85b0df92047dd6b2fb24148486d531a80945bb7e7e1ee5d1da28a992d26f7f3111ae1994e76ca6c4685b6e4aa7707516a19dd0ee6beb6951ae64041fb
ssdeep: 3072:zy//ypzPN5mJg0uZHZ045x+HVLSQEOJHsMFlH1IJLB:zy/IlEPeAz5JH7rVI
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalName: sojbmoeminu.ihe
ProductVersion: 8.19.590.38
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0129 0x0171

Trojan.Generic.30181956 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.MSIL.Agent.i!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Agent.CobaltStrike
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3488576
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Tnega.95c87f62
K7GWTrojan ( 005894161 )
Cybereasonmalicious.e8a5f2
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMNL
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Generic-9894234-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderTrojan.Generic.30181956
NANO-AntivirusTrojan.Win32.Zenpak.jbxtnh
ViRobotTrojan.Win32.Z.Zenpak.182272
MicroWorld-eScanTrojan.Generic.30181956
Ad-AwareTrojan.Generic.30181956
SophosMal/Generic-S + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34236.lq0@aKpjyqfO
TrendMicroTROJ_FRS.0NA103IM21
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
FireEyeGeneric.mg.ef799b5261fd69b5
EmsisoftTrojan.Generic.30181956 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.och
WebrootW32.Trojan.Gen
AviraTR/AD.Swrort.ybkjm
MicrosoftTrojan:Win32/Tnega!MSR
ArcabitTrojan.Generic.D1CC8A44
GDataTrojan.Generic.30181956
AhnLab-V3CoinMiner/Win.Glupteba.R441747
Acronissuspicious
McAfeePacked-GDT!EF799B5261FD
MAXmalware (ai score=83)
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103IM21
RisingTrojan.Kryptik!1.D9B3 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73832973.susgen
FortinetW32/Packed.GDT!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.Generic.30181956?

Trojan.Generic.30181956 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment