Trojan

Trojan.Generic.30226154 removal tips

Malware Removal

The Trojan.Generic.30226154 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30226154 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (18 unique times)
  • Starts servers listening on 0.0.0.0:5923
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

microsoft-com.mail.protection.outlook.com
defeatwax.ru
158.102.105.176.dnsbl.sorbs.net
158.102.105.176.bl.spamcop.net
158.102.105.176.zen.spamhaus.org
158.102.105.176.sbl-xbl.spamhaus.org
158.102.105.176.cbl.abuseat.org
fastpool.xyz
mail.yaxmail.net
am2mxi03.aig.com
sohumx1.sohu.com
mail.h-email.net
smtp.ext.microfocus.com
mx1.comcast.net

How to determine Trojan.Generic.30226154?


File Info:

crc32: 8B9D6E66
md5: 25d5d497838fd97828d3deccd8ab3dcf
name: 25D5D497838FD97828D3DECCD8AB3DCF.mlw
sha1: 9a62b4fee040e18f55e9b05cba21fa4e8befb604
sha256: 81a5160e2ab8b3de21042416f371c9c95118c6d3f0d7f08bb1fd1158dfcba31c
sha512: ba019bb8f104d260f67f6a897185457069b269c3796549becd8928e9e28d2654bfee42af9a6361bb77c6698df6519b37278a1368e50615618e9ff197f56e82c4
ssdeep: 3072:GahrLMIrtlHeUI0gNZG9VhCtD5Yjnx6oxeYQ:Gahn7rthKGtx6oe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sajbmoimizu.ise
ProductVersion: 8.79.590.35
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0129 0x00a9

Trojan.Generic.30226154 also known as:

K7AntiVirusTrojan ( 005880fc1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.15523
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Tofsee
ALYacTrojan.Generic.30226154
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3497885
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005880fc1 )
Cybereasonmalicious.ee040e
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HMPQ
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Packed.Generic-9896741-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.Generic.30226154
MicroWorld-eScanTrojan.Generic.30226154
TencentWin32.Backdoor.Tofsee.Hssr
Ad-AwareTrojan.Generic.30226154
SophosMal/Generic-R + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34170.iq0@aauqX!jO
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.25d5d497838fd978
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.evm
AviraTR/Crypt.Agent.svlyy
Antiy-AVLTrojan/Generic.ASMalwS.34A2C44
MicrosoftTrojan:Win32/Azorult.RMA!MTB
GDataTrojan.Generic.30226154
AhnLab-V3CoinMiner/Win.Glupteba.R442682
Acronissuspicious
McAfeePacked-GDT!25D5D497838F
MAXmalware (ai score=82)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DIP21
RisingTrojan.Kryptik!1.D9C1 (CLASSIC)
YandexTrojan.Kryptik!yWusze8GOyo
IkarusTrojan.Win32.Crypt
FortinetW32/Tofsee.BO!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Trojan.Generic.30226154?

Trojan.Generic.30226154 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment