Trojan

About “Trojan.Generic.8301559” infection

Malware Removal

The Trojan.Generic.8301559 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.8301559 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Generic.8301559?


File Info:

name: 44BB4FCBD68815EFEF74.mlw
path: /opt/CAPEv2/storage/binaries/5353ffe8e8e2d2115d5e15f21c5f777e47e1250f362ba8618f12fb8f2aaaa957
crc32: A5FE5689
md5: 44bb4fcbd68815efef74ee1d5951f1e9
sha1: 096d4df98cfceba95498d4902054c14d5dae0f88
sha256: 5353ffe8e8e2d2115d5e15f21c5f777e47e1250f362ba8618f12fb8f2aaaa957
sha512: 39409ae47b132e6812e88b141a6f402bdb579429660bb0a579645b744e2d278ea7185edb311afca2b3a23894225d62722ad8c4d5e3deb8f9a35285430736b0d7
ssdeep: 6144:RcvdT5F2CZYt3ReVElWWwBsoIMGKtNI77oz8+4xcGgfXvYDsd96:OVT5FLZY7eSWW2slMPU7o94xctXAD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA74126279188D93F5A2913666D76F204700AC33196D1C97D6D0BF0E7E7AEF1FA1280B
sha3_384: ea86d454a24c53d7da0bd55cecbe7db6e9e1dda46160dcbc96f15c0b6c50de337bf1fcd04da572db728242cdfd99c5ee
ep_bytes: 60be002048008dbe00f0f7ffc787a080
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Generic.8301559 also known as:

LionicTrojan.Win32.Hesv.4!c
MicroWorld-eScanTrojan.Generic.8301559
FireEyeTrojan.Generic.8301559
McAfeeArtemis!44BB4FCBD688
CylanceUnsafe
VIPRETrojan.Generic.8301559
SangforTrojan.Win32.Generic.8
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/DRMSoft.28831fae
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZelphiF.34592.umJfaWxj9fgd
CyrenW32/Dropper.BQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.DRMSoft.E suspicious
TrendMicro-HouseCallTROJ_GEN.R067C0OH622
Paloaltogeneric.ml
ClamAVWin.Dropper.Mudrop-6877575-0
KasperskyHEUR:Trojan.Win32.Hesv.gen
BitDefenderTrojan.Generic.8301559
NANO-AntivirusTrojan.Win32.Crypted.efrgcp
CynetMalicious (score: 99)
AvastWin32:Trojan-gen
Ad-AwareTrojan.Generic.8301559
EmsisoftTrojan.Generic.8301559 (B)
ComodoMalware@#18khyp3kp9cor
DrWebTrojan.MulDrop2.62141
ZillyaDropper.Mudrop.Win32.5040
TrendMicroTROJ_GEN.R067C0OH622
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
SentinelOneStatic AI – Malicious PE
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
APEXMalicious
GDataTrojan.Generic.8301559
JiangminTrojanDropper.Mudrop.bnr
AviraHEUR/AGEN.1232672
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.24D
ViRobotTrojan.Win32.Z.Mudrop.341902
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32TrojanDropper.Mudrop
ALYacTrojan.Generic.8301559
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.DR.Mudrop!godWHhr9F/w
IkarusTrojan-Banker.Win32.Banker
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Multidr
AVGWin32:Trojan-gen
Cybereasonmalicious.bd6881
PandaTrj/Genetic.gen

How to remove Trojan.Generic.8301559?

Trojan.Generic.8301559 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment