Trojan

Should I remove “Trojan.Generic.30517923”?

Malware Removal

The Trojan.Generic.30517923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30517923 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Trojan.Generic.30517923?


File Info:

name: 74E785D1E2C0CE72587F.mlw
path: /opt/CAPEv2/storage/binaries/64895c5fa6689c6aff986b6e1f65f75d4e9c15b57b6f89582c93064fa0643a69
crc32: BADB2D1E
md5: 74e785d1e2c0ce72587fb6b63b6083c1
sha1: cfcebddcd9578f2ea80fa14670a94f02f86bee42
sha256: 64895c5fa6689c6aff986b6e1f65f75d4e9c15b57b6f89582c93064fa0643a69
sha512: 3760cb8cd1a6d00cbb06847c4d09a7caf06d5c289154d40e425b95a6698085d1c58add68d89bb0a98c168e9e004de060b9b75a147f0a9428ffbafeffb284899d
ssdeep: 196608:U+gqLKB2pBcZBUPB6qZ9oMwv3Js4OsJrLCJuBIPxd2lL:U+jOB2pycky92v3ytsJXCFXQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16156E130768BC52BD5A605B15A3CDBAF5168BFB60F6150C7A3E42E6E45B48C31332E27
sha3_384: f57eef07308764147c6201b2920418a2e9cea81cfc628285e3a63284b7f4f5a5187bebf93ac2b642f514426ca377ade8
ep_bytes: e86c060000e97afeffffcccccccccc51
timestamp: 2021-07-27 13:39:02

Version Info:

CompanyName: Geeks3D
FileDescription: Fur Images Converter Installer
FileVersion: 3.3.2.0
InternalName: ImagesConverter
LegalCopyright: Copyright (C) 2021 Geeks3D
OriginalFileName: ImagesConverter.exe
ProductName: Fur Images Converter
ProductVersion: 3.3.2.0
Translation: 0x0409 0x04b0

Trojan.Generic.30517923 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Siggen15.54562
MicroWorld-eScanTrojan.Generic.30517923
FireEyeTrojan.Generic.30517923
ALYacTrojan.Generic.30517923
ESET-NOD32multiple detections
KasperskyTrojan-Downloader.Win32.Deyma.che
BitDefenderTrojan.Generic.30517923
AvastWin32:DangerousSig [Trj]
Ad-AwareTrojan.Generic.30517923
EmsisoftTrojan.Generic.30517923 (B)
GDataTrojan.Generic.30517923
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D1D1AAA3
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
AhnLab-V3Trojan/Win.DangerousSig.C4789373
YandexTrojanSpy.Stealer!vfbiB48MZEM
AVGWin32:DangerousSig [Trj]

How to remove Trojan.Generic.30517923?

Trojan.Generic.30517923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment