Trojan

Trojan.Generic.30234880 (B) removal guide

Malware Removal

The Trojan.Generic.30234880 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30234880 (B) virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan.Generic.30234880 (B)?


File Info:

name: B7B2EAFE7CA10B161742.mlw
path: /opt/CAPEv2/storage/binaries/c3c4f0fd030e1d799a481d844e236c7416f095b7cf3e1d66146ee6197670fb9e
crc32: 9B4989FF
md5: b7b2eafe7ca10b1617420010f2585c0c
sha1: 0ce6ca61c1d55054bb3d51c6305f642e33cbe015
sha256: c3c4f0fd030e1d799a481d844e236c7416f095b7cf3e1d66146ee6197670fb9e
sha512: ec5656a2dbdd7050c33d3296f93a5c1db0ff01a7e26aaf55149c18bf1c678c93fe5c38701d81e14434593811c196483f65c454cb2f5d90f1dc6df95d9df7db11
ssdeep: 384:FFnwR2IT1XKqC9YATzWLkAzFABlbNbqxtV:LwRrT16WFFABbbqZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3B2E73C6AE91572E3BBCFB685F555C6B974B4623D12D80D00DA43880823F66EDE1B1E
sha3_384: ca817051ced613ded7eaa5ebbc884e7bfb0ef955fb4635292b2dcf74f5b5ce11dbf811e98e9354334b7a8a8ddd55ad36
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-10-09 18:19:12

Version Info:

0: [No Data]

Trojan.Generic.30234880 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lY5V
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.30234880
FireEyeGeneric.mg.b7b2eafe7ca10b16
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDownloader-FBVZ!B7B2EAFE7CA1
CylanceUnsafe
ZillyaDownloader.Waski.Win32.13050
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 004b972f1 )
Cybereasonmalicious.e7ca10
BaiduWin32.Trojan-Downloader.Waski.k
CyrenW32/Upatre.KG.gen!Eldorado
SymantecDownloader.Upatre!gm
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.Upatre-7598844-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.30234880
NANO-AntivirusTrojan.Win32.DownLoad3.cnbuup
AvastWin32:Downloader-WID [Trj]
TencentMalware.Win32.Gencirc.10b0cbcc
Ad-AwareTrojan.Generic.30234880
EmsisoftTrojan.Generic.30234880 (B)
ComodoTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
DrWebTrojan.DownLoad3.28161
VIPRETrojan-Downloader.Win32.Upatre.a (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
SophosML/PE-A + Mal/EncPk-ACO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrzv
eGambitUnsafe.AI_Score_96%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2C5FE1D
GridinsoftRansom.Win32.Gen.sa
ArcabitTrojan.Generic.D1CD5900
MicrosoftTrojan:Win32/Upatre.AMN!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.bqY@aSzRtMd
ALYacTrojan.Generic.30234880
MAXmalware (ai score=85)
VBA32Trojan.Downloader
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Downloader-WID [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.30234880 (B)?

Trojan.Generic.30234880 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment