Trojan

About “Trojan:Win32/Seodec.A” infection

Malware Removal

The Trojan:Win32/Seodec.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Seodec.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

a.15111358088.cn
open.baidu.com
www.baidu.com
ocsp.globalsign.com
crl.globalsign.net
ocsp2.globalsign.com
crl.globalsign.com

How to determine Trojan:Win32/Seodec.A?


File Info:

crc32: 0530DD6E
md5: 360053e7d0927905d2b6fd5a04a13e9b
name: 360053E7D0927905D2B6FD5A04A13E9B.mlw
sha1: c4df7ad6fbe4390248bc7745be5214c630106c55
sha256: 0d1bf588c8a745b156cdb87d8e6264da2e0d45833efdd52f44ed800d6514af20
sha512: 058a19069f4f80c39084bc4416fb6296f167eb13b60e21f1c066596c7b931df52b22b9fb426bd93a7b3f41ee5c1dcd05648f1f2401f9bfae07ac5723ecb08849
ssdeep: 24576:va7qagV1A15sShxBc8dsiXobxwrSdjj4f:S2aU15StcSswofPo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Seodec.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Multi.Generic.mbME
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealDownloader.AdLoad.12395
ALYacGen:Variant.Symmi.50925
CylanceUnsafe
ZillyaTrojan.FlyStudio.Win32.21298
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Seodec.0da87288
K7GWTrojan ( 004c20da1 )
Cybereasonmalicious.7d0927
CyrenW32/S-7c7d1126!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.ONL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9820446-0
Kasperskynot-a-virus:UDS:Downloader.Win32.Adload.heur
BitDefenderGen:Variant.Symmi.50925
NANO-AntivirusTrojan.Win32.FlyStudio.dkqboa
MicroWorld-eScanGen:Variant.Symmi.50925
TencentWin32.Trojan.Symmi.Lhcy
Ad-AwareGen:Variant.Symmi.50925
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34236.crW@aqm6t5db
VIPRETrojan.Win32.Seodec.a (v)
TrendMicroTROJ_GEN.R002C0DJR21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.360053e7d0927905
EmsisoftGen:Variant.Symmi.50925 (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.AdLoad.mio
AviraTR/Seodec.ztzyd
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.286F28C
MicrosoftTrojan:Win32/Seodec.A
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.AdLoad.heur
GDataGen:Variant.Symmi.50925
AhnLab-V3Trojan/Win32.Agent.R158502
Acronissuspicious
McAfeeGenericRXAG-YI!360053E7D092
MAXmalware (ai score=84)
VBA32BScope.TrojanDownloader.Genome
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJR21
YandexTrojan.GenAsa!QUuzJui7SXo
IkarusTrojan.Win32.Seodec
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Seodec.A?

Trojan:Win32/Seodec.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment