Trojan

Trojan.Generic.30233276 (B) removal guide

Malware Removal

The Trojan.Generic.30233276 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30233276 (B) virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan.Generic.30233276 (B)?


File Info:

name: BDF61D56E0E98361B279.mlw
path: /opt/CAPEv2/storage/binaries/baed83da52366ae2644ff3501129917e4938d97642603808b7f5d42a18f1a1bc
crc32: 0D204618
md5: bdf61d56e0e98361b2796179e323ccb0
sha1: a9803cbbe9f5155ac8aaceea0e8297c88358df7b
sha256: baed83da52366ae2644ff3501129917e4938d97642603808b7f5d42a18f1a1bc
sha512: 7e3ef8c58b85ff9d47b80d25134f2d94b5f40b0891f40cab29c2892dabef3f216efd24e25d14c2267a2ce1a8acdc8c720433c101c1da464d7389adfb897a8434
ssdeep: 96:QtTcnngncTXghZd5WeOU4GQsPb5CyeYWSUqK4pWlvTE6YLLLoGQLLLpwwNiEA:QpGWcTQvbqFzKb9VfK9kp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12802DF796BE61A72F37B8FBA46F581C2B574F8213C02A90C80D947451462FA6DDB0E1B
sha3_384: f5b9cec956597753c473de06acb29f440e5d3b32095bcbfe834dd68624f7024c789822add8c5e89112da147970359e97
ep_bytes: b800404000608da800c0ffff680463d5
timestamp: 2013-08-23 14:01:36

Version Info:

0: [No Data]

Trojan.Generic.30233276 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.8528
MicroWorld-eScanTrojan.Generic.30233276
FireEyeGeneric.mg.bdf61d56e0e98361
McAfeeDownloader-FBSK!ABD169D8F58A
CylanceUnsafe
ZillyaDownloader.Waski.Win32.8646
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0053178a1 )
K7GWTrojan-Downloader ( 0053178a1 )
Cybereasonmalicious.6e0e98
BitDefenderThetaAI:Packer.DD8AEA1E1D
CyrenW32/Upatre.LR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.AJ
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Upatre-9886864-0
KasperskyTrojan-Downloader.Win32.Small.gen
BitDefenderTrojan.Generic.30233276
NANO-AntivirusTrojan.Win32.Downloader.jdhmwf
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b0cec3
Ad-AwareTrojan.Generic.30233276
EmsisoftTrojan.Generic.30233276 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AX@7t0ehr
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
SophosML/PE-A + Troj/Upatre-XO
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan.Generic.cdnmu
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.2616CE8
MicrosoftTrojan:Win32/Zbot.DC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R256307
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.Generic.30233276
TACHYONTrojan-Downloader/W32.Convagent.24864
MalwarebytesMalware.AI.3927986274
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:mzUq52APr0uFYhFsETMlwA)
YandexTrojan.GenAsa!w6f6bF9mr2E
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_54%
FortinetW32/Tiny.NIV!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Generic.30233276 (B)?

Trojan.Generic.30233276 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment