Trojan

Trojan.GenericFC.S30155698 removal

Malware Removal

The Trojan.GenericFC.S30155698 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericFC.S30155698 virus can do?

  • Authenticode signature is invalid
  • CAPE detected the XWorm malware family

How to determine Trojan.GenericFC.S30155698?


File Info:

name: B4AD436161DEB40E8D23.mlw
path: /opt/CAPEv2/storage/binaries/96f1ed847e5dd79ec16140b7a60279b2c921e53f48430a96227be157f492c0d2
crc32: 648E429D
md5: b4ad436161deb40e8d2302e3c061a582
sha1: 9d00e6dede722c4fc21a7335c2e73d2a70c2cef2
sha256: 96f1ed847e5dd79ec16140b7a60279b2c921e53f48430a96227be157f492c0d2
sha512: 47612ae0c2bd72f5961c39a4f6b21b0196536a822ac01ee1c4ac8ad8e663e61436ceda5dc290b1f3be5b766ce3dce41b842c2469a2d247cc122cb21fd96e0d09
ssdeep: 768:Yecbl/b37gMYAoRFNk2uBFE9RYvOqhFbq:Hcx6Nk24FE9RYvOqn+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197D23B483BE84327D6FE2FB229B2A10103759507D923EF5F5CD885A7AF67B8146013E6
sha3_384: 775f19abf608110058003058d3c39e85cd2582852e2db01948a373dd3c62cf2e4a8cf9c594cc0aeed5c0312da938e3b2
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-04 09:11:21

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: XClient.exe
LegalCopyright:
OriginalFilename: XClient.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.GenericFC.S30155698 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S30155698
ALYacIL:Trojan.MSILZilla.25346
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3231769
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00592e8b1 )
K7AntiVirusTrojan ( 00592e8b1 )
BitDefenderThetaGen:NN.ZemsilF.36348.bm0@aOR@mqo
VirITTrojan.Win32.Genus.RRS
CyrenW32/MSIL_Agent.BUD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.DWN
APEXMalicious
ClamAVWin.Packed.njRAT-10002074-1
KasperskyHEUR:Trojan.MSIL.PowerShell.gen
BitDefenderIL:Trojan.MSILZilla.25346
MicroWorld-eScanIL:Trojan.MSILZilla.25346
AvastWin32:InjectorX-gen [Trj]
RisingBackdoor.XWorm!1.E338 (CLASSIC)
TACHYONTrojan/W32.DN-PowerShell.30720
EmsisoftIL:Trojan.MSILZilla.25346 (B)
DrWebTrojan.PWS.Stealer.35765
VIPREIL:Trojan.MSILZilla.25346
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b4ad436161deb40e
SophosTroj/Agent-BJXT
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/MSIL.PowerShell
MicrosoftTrojan:MSIL/XWorm.C!MTB
ArcabitIL:Trojan.MSILZilla.D6302
ZoneAlarmHEUR:Trojan.MSIL.PowerShell.gen
GDataMSIL.Backdoor.XWormRAT.B
GoogleDetected
AhnLab-V3Backdoor/Win.AsyncRat.C5366153
Acronissuspicious
McAfeeGenericRXWB-PG!B4AD436161DE
MAXmalware (ai score=80)
VBA32Backdoor.MSIL.XWorm.gen
MalwarebytesGeneric.Malware.AI.DDS
TencentTrojan.Msil.Blocker.16000561
IkarusTrojan.MSIL.XWorm
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DWN!tr
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.ede722
DeepInstinctMALICIOUS

How to remove Trojan.GenericFC.S30155698?

Trojan.GenericFC.S30155698 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment