Trojan

Trojan.Generic.8302128 removal

Malware Removal

The Trojan.Generic.8302128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.8302128 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Trojan.Generic.8302128?


File Info:

name: 84F38F6DEE86B946B600.mlw
path: /opt/CAPEv2/storage/binaries/7958b889a48c2411bf46e3c94acc141866862bafb860bddf0de2140f058accd1
crc32: 936C4A85
md5: 84f38f6dee86b946b600cfeef07dad1a
sha1: 453463f20d4393a9ccf729ed2fed2fd0eb8d87cb
sha256: 7958b889a48c2411bf46e3c94acc141866862bafb860bddf0de2140f058accd1
sha512: 0ccd4864b51e2b1fcc2bac6c971d7b135606a50a6b558e6b54b25ada8113899af5f6a909a61821277adb9e8734afe3680f2473e3f189ad0d26613083f6c913dd
ssdeep: 3072:Cp5qYw8n2dDwEH9HvbINZ+ca64Rx/ZxbqwqQQ:COYnn2yEH9H8NZ+RHRxhx2OQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AF3E103BA95817BE053093626E592921E7EBD222B35145B3F4C16BE8F713D3097DFA2
sha3_384: 99452e1dbae75153974ef7cc44568d06beb1ed0adb28b1d88f27e74199ec3bf583fa881fb018cf8a4750e41306deabfe
ep_bytes: e8aa140000e989feffff660fefc05153
timestamp: 2012-07-02 17:41:01

Version Info:

0: [No Data]

Trojan.Generic.8302128 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.lzjF
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.84f38f6dee86b946
ALYacTrojan.Generic.8302128
CylanceUnsafe
VIPRETrojan.Win32.Zbot.aft (v)
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 002f7a301 )
AlibabaTrojanPSW:Win32/Bulta.ccdfc7b0
K7GWPassword-Stealer ( 002f7a301 )
Cybereasonmalicious.dee86b
BitDefenderThetaGen:NN.ZexaF.34212.kqW@a881Eqpi
VirITTrojan.Win32.Stealer.BKK
CyrenW32/Zbot.FI.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/PSW.Agent.NTM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.8302128
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.Generic.8302128
AvastSf:ShellCode-AU [Trj]
TencentWin32.Trojan.Generic.Ecud
Ad-AwareTrojan.Generic.8302128
EmsisoftTrojan.Generic.8302128 (B)
ComodoTrojWare.Win32.Kryptik.AHUE@4pidto
DrWebTrojan.PWS.Stealer.946
ZillyaTrojan.Kryptik.Win32.254534
McAfee-GW-EditionBehavesLike.Win32.PUPXBO.ch
SophosMal/Generic-R + Mal/Wonton-S
IkarusPUA.Multibar.Ff
GDataTrojan.Generic.8302128
JiangminTrojan/Generic.aftgz
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.24D5A2
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Fareit
AhnLab-V3Backdoor/Win32.Cycbot.R30130
Acronissuspicious
McAfeeGenericR-EAJ!84F38F6DEE86
MAXmalware (ai score=99)
VBA32BScope.TrojanPSW.Stealer
MalwarebytesMachineLearning/Anomalous.100%
RisingStealer.Agent!8.C2 (CLOUD)
YandexTrojan.GenAsa!zbkCm8VIMko
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.AAN!tr
AVGSf:ShellCode-AU [Trj]
PandaTrj/Plaste.a
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.Generic.8302128?

Trojan.Generic.8302128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment