Trojan

How to remove “Trojan.Generic.30212648”?

Malware Removal

The Trojan.Generic.30212648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30212648 virus can do?

  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Generic.30212648?


File Info:

name: 34F61ADA500F7018087D.mlw
path: /opt/CAPEv2/storage/binaries/e7df4882e7b0a2559c0ac14f519ccda41f3a840bb82bd7a8a64d5b1002f38c5f
crc32: D21638C5
md5: 34f61ada500f7018087d06af36997d06
sha1: 412d12b8a3cff28378019086576044c29476135d
sha256: e7df4882e7b0a2559c0ac14f519ccda41f3a840bb82bd7a8a64d5b1002f38c5f
sha512: 965d20a55952a51eb78f1b8e9ec1253c04a768110791b272817213257944c0d6d8f0f6d17228f6280c713c51ca92da72ac4fe4809c644b5aee7c0205b69785ed
ssdeep: 768:HT1g40wSXvdMx+v3fUFqFRFo6kF7xNvCMUM33ScGyTjUOXRyrnfuH:Hxg2SfdMw3KeE52ayEj/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15433C0386EE95672D3BBCEB6C6F655C6F935B4233D02980D40DA43840C23F56EDA1A1E
sha3_384: 6b1ab1d719eed8f2b41d97c3d83d0423beebfd6bfc1ecae340ba12ceccf81990cb809082e469bc443a2cb1614be8ad89
ep_bytes: 558d6c248881ecd808000053565733db
timestamp: 2014-05-07 11:58:56

Version Info:

0: [No Data]

Trojan.Generic.30212648 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.30212648
FireEyeGeneric.mg.34f61ada500f7018
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Generic.30212648
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 004941701 )
K7AntiVirusTrojan-Downloader ( 004941701 )
CyrenW32/Upatre.JY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
ClamAVWin.Malware.Upatre-6997924-0
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderTrojan.Generic.30212648
NANO-AntivirusTrojan.Win32.Zbot.euxmcg
AvastWin32:Upatre-V [Trj]
TencentMalware.Win32.Gencirc.10b0cd9b
Ad-AwareTrojan.Generic.30212648
EmsisoftTrojan.Generic.30212648 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
DrWebTrojan.DownLoad4.14155
ZillyaDownloader.Waski.Win32.8133
McAfee-GW-EditionBehavesLike.Win32.Downloader.qz
SophosML/PE-A + Troj/Upatre-XO
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fkxb
AviraHEUR/AGEN.1136562
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.229FAA0
ViRobotTrojan.Win32.Downloader.5632.LY
MicrosoftTrojan:Win32/Zbot.SIBG3!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C369973
Acronissuspicious
McAfeeDownloader-FBVZ!34F61ADA500F
TACHYONTrojan-Spy/W32.ZBot.53476
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Downloader
RisingTrojan.Generic@ML.100 (RDML:YBmmgo6TSBST2LKCowiVzA)
YandexTrojan.GenAsa!uGSW6+/pwxg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Waski.B!tr
BitDefenderThetaGen:NN.ZexaF.34294.dyZ@aGXohAki
AVGWin32:Upatre-V [Trj]
Cybereasonmalicious.a500f7
PandaTrj/Genetic.gen

How to remove Trojan.Generic.30212648?

Trojan.Generic.30212648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment