Trojan

What is “Trojan.Generic.30329635”?

Malware Removal

The Trojan.Generic.30329635 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30329635 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the DarkComet malware family
  • A script or command line contains a long continuous string indicative of obfuscation
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Creates known Fynloski/DarkComet mutexes

Related domains:

sommerishere.sytes.net
ommerishere.sytes.net

How to determine Trojan.Generic.30329635?


File Info:

name: FD4C226FFF4DF39D966E.mlw
path: /opt/CAPEv2/storage/binaries/e0cd701f11cf6c56b93142f9ff940d84b05b17052e58f75ed43dda55329c84c4
crc32: 72A3F469
md5: fd4c226fff4df39d966e858a8e1e55b3
sha1: dd71284e50a5650d1e74c0db093510c18ace33a7
sha256: e0cd701f11cf6c56b93142f9ff940d84b05b17052e58f75ed43dda55329c84c4
sha512: d0839f164a1c589058e094ccc987a39802cbb86a4484feba150bbf2d181999042155e299e9f01ee12f30efdb4954fc6024ed0752db251d5b589a0a7c2d933345
ssdeep: 12288:HBjDbgTLHiQKV1EWzlH5I9GySnouCuNI9OeM1QwI:hjBQKPEWzjon9OeM1k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113C423A09BD54B12EB95583A049525DB02E8EAABE7335E56040F7378BE1B6C00973FE4
sha3_384: 61694e6d36113c91bc8291e33fe956515c288db54c5338727097e5734a98912faf356f5757868a5fdf5e1aae0fbc70e3
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-05 09:08:27

Version Info:

Translation: 0x0000 0x04b0
Comments: HSlPO
FileDescription: OYLqR
FileVersion: 50.89.18.80
InternalName: DEomepkj.exe
LegalCopyright: vQxDS
OriginalFilename: DEomepkj.exe
ProductName: vkciM
ProductVersion: 50.89.18.80
Assembly Version: 40.43.95.66

Trojan.Generic.30329635 also known as:

LionicTrojan.Win32.Generic.m2oZ
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.30329635
FireEyeGeneric.mg.fd4c226fff4df39d
CAT-QuickHealBackdoor.Generic
ALYacTrojan.Generic.30329635
CylanceUnsafe
K7AntiVirusTrojan ( 0049d28c1 )
AlibabaBackdoor:Win32/Injector.269b158b
K7GWTrojan ( 0049d28c1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34294.Im1@aWtJl5m
CyrenW32/MSIL_Kryptik.FVK.gen!Eldorado
SymantecPacked.Generic.484
ESET-NOD32a variant of MSIL/Injector.EIU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderTrojan.Generic.30329635
AvastMSIL:GenMalicious-CH [Trj]
TencentMalware.Win32.Gencirc.11d1eef6
Ad-AwareTrojan.Generic.30329635
EmsisoftTrojan.Generic.30329635 (B)
DrWebBackDoor.Bladabindi.1056
VIPRETrojan.MSIL.Injector.eng (v)
TrendMicroTROJ_GEN.R002C0OKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A + Troj/dnSauce-G
IkarusTrojan.Win32.Fsysna
GDataTrojan.Generic.30329635
JiangminBackdoor.Generic.cgkd
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34B78AE
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftRansom.Win32.Bladabindi.sa
ViRobotTrojan.Win32.Z.Injector.557120.A
MicrosoftTrojan:Win32/Ymacco.ABE0
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R108379
McAfeeArtemis!FD4C226FFF4D
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0OKN21
YandexTrojan.Injector!7xw3k4l9H0M
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injector.ENG!tr
AVGMSIL:GenMalicious-CH [Trj]
Cybereasonmalicious.fff4df
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.30329635?

Trojan.Generic.30329635 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment