Trojan

Trojan.Generic.30338004 removal instruction

Malware Removal

The Trojan.Generic.30338004 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30338004 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
hsiens.xyz
a.goatgame.co
romkaxarit.tumblr.com
safialinks.com
best-link-app.com
wfsdragon.ru
cdn.discordapp.com
ocsp.digicert.com
ipinfo.io

How to determine Trojan.Generic.30338004?


File Info:

crc32: F3242186
md5: 9acc8ada572b90cccac0213ab6b218b0
name: 9ACC8ADA572B90CCCAC0213AB6B218B0.mlw
sha1: 2408a360552642121ff695c881e38b3ec583f143
sha256: 76d7f639d56e61b280e2bbe6adb4d326d73c508cf1f4684223673f018d0f3247
sha512: d35bc31f02d3cf4ee85a9ca9ec13a679cc752af666b17016db1e0a3640f8e3e30312976f2bfd4e472ae72555c9029b9788e7bcc0e80d71fae036171c04188711
ssdeep: 49152:xcBfEwJ84vLRaBtIl9mVvcSsM0Xvo9K0JLrTvoaEQnUn/6beZyzp6NC1:xJCvLUBsgQXN0JLIPnnRyVIi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 19.00
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 19.00
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Trojan.Generic.30338004 also known as:

K7AntiVirusTrojan ( 0058270d1 )
LionicTrojan.Win32.AdLoad.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader42.596
CynetMalicious (score: 100)
CAT-QuickHealTrojan.SabsikIH.S21959152
ALYacTrojan.Generic.30338004
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/StopCrypt.1017
K7GWTrojan ( 005809441 )
CyrenW32/ArkeiStealer.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Packed.Barys-9859531-0
KasperskyTrojan-Downloader.Win32.Zenlod.lvv
BitDefenderTrojan.Generic.30338004
NANO-AntivirusTrojan.Win32.Stop.jajcnd
ViRobotTrojan.Win32.Z.Arkeistealer.2732998
MicroWorld-eScanTrojan.Generic.30338004
TencentWin32.Trojan.Stop.Hwwq
Ad-AwareTrojan.Generic.30338004
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34266.n88baOE@FOp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeTrojan.Generic.30338004
EmsisoftTrojan.Generic.30338004 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Injector.dx
AviraEXP/YAV.Minerva.wwfgi
eGambitUnsafe.AI_Score_85%
Antiy-AVLTrojan/Generic.ASMalwS.3496440
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/ArkeiStealer.DB!MTB
ArcabitTrojan.Generic.D1CEEBD4
GDataTrojan.Generic.30338004
McAfeeArtemis!9ACC8ADA572B
MAXmalware (ai score=80)
VBA32Trojan.ArkeiStealer
MalwarebytesTrojan.Dropper.SFX.Generic
PandaTrj/CI.A
RisingDownloader.Agent!1.D93C (CLASSIC)
MaxSecureTrojan.Malware.11716371.susgen
FortinetW32/BSE.4Q7Q!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Trojan.Generic.30338004?

Trojan.Generic.30338004 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment