Trojan

Trojan.GenericRI.S30174122 removal tips

Malware Removal

The Trojan.GenericRI.S30174122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S30174122 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.GenericRI.S30174122?


File Info:

name: C92110533AD11E70EE06.mlw
path: /opt/CAPEv2/storage/binaries/271165546b2b7c80c33eb087500d114ec3f0357403790ec793bc0378ed02b78c
crc32: 9A4E185D
md5: c92110533ad11e70ee06eb2eb668baca
sha1: 115385bdf22e837bf5b89eef1e7b12cb52179963
sha256: 271165546b2b7c80c33eb087500d114ec3f0357403790ec793bc0378ed02b78c
sha512: 69a30a6a1a7c5f87f0ff056847b806f4c6a11265eea6e3ac5f5a15ba04025c37c31fc9790f83d677f0db431a9b8d2c38ea990825bca90b6bb9186ec32d23b825
ssdeep: 6144:Da6znlkcLXP4JkKYRahbkckECzJLaQVbU5:e6KcLXPHRabkcklJLJbU5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC549D063605EA72F0E7023519E94BA2AB25BC34A77781EFB4C5736D2173BE90DB8750
sha3_384: a1133a9ee6a7587601447226fe99ffbb1f77421e865874ad771405b706b14a932c99d3fd1ae5d17964754d7b08938410
ep_bytes: 60bb000000008a8b0010400080e947c0
timestamp: 2011-07-11 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Trojan.GenericRI.S30174122 also known as:

LionicTrojan.Win32.Nobady.4!c
DrWebTrojan.MulDrop5.42246
MicroWorld-eScanGen:Variant.Zusy.455463
ClamAVWin.Malware.Razy-9759519-0
FireEyeGeneric.mg.c92110533ad11e70
CAT-QuickHealTrojan.GenericRI.S30174122
McAfeeGenericRXOB-DF!C92110533AD1
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaTrojan.Agent.Win32.3466594
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b494b1 )
AlibabaTrojan:Win32/Aenjaris.4a834683
K7GWTrojan ( 004b494b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36250.sK3@aShChWpi
CyrenW32/Agent.GHH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Nobady.pef
BitDefenderGen:Variant.Zusy.455463
NANO-AntivirusTrojan.Win32.Patched.foubml
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.zl
EmsisoftGen:Variant.Zusy.455463 (B)
F-SecureTrojan.TR/Agent.unbar
VIPREGen:Variant.Zusy.455463
TrendMicroTROJ_GEN.R002C0DEE23
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosMal/Agent-AWE
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BadJoke.J
AviraTR/Agent.unbar
Antiy-AVLTrojan/Win32.Agent.WTK
XcitiumTrojWare.Win32.Aenjaris.ABC@8hq1l4
ArcabitTrojan.Zusy.D6F327
ZoneAlarmHEUR:Trojan.Win32.Nobady.pef
MicrosoftTrojan:Win32/Aenjaris.AL!bit
GoogleDetected
AhnLab-V3Trojan/Win.DF.R566591
VBA32SScope.Malware-Cryptor.Aenjaris
ALYacGen:Variant.Zusy.455463
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEE23
RisingTrojan.Agent!1.A728 (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.33ad11
DeepInstinctMALICIOUS

How to remove Trojan.GenericRI.S30174122?

Trojan.GenericRI.S30174122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment