Categories: Malware

How to remove “DarkHotel.31”?

The DarkHotel.31 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What DarkHotel.31 virus can do?

  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rmtp.undo.it

How to determine DarkHotel.31?


File Info:

crc32: EBC409D5md5: c47da9b3843466df1eebc2357d52e8c1name: chrome.exesha1: 865e6292788410dc881ac895ad5bfb4a314cb69fsha256: 728afaf64e3efb6193ff0c687fb5ace6f1e4fedfdec87c78ef4bdf8088b3a3d1sha512: 6cf2d17fdc07f1d489d9c3b7e93f52d1522663fac4481e9854958ec21e9f2da4084b0a1ef993e4966889172c501ac6470b02b8965602f82a468df27286ed1bb5ssdeep: 768:qDDXLNd8f00EAcaN7YIrNG/CDSjgID3267oV:qDPNN0EAnyUSjVoVtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

DarkHotel.31 also known as:

MicroWorld-eScan Gen:Variant.DarkHotel.31
McAfee Artemis!C47DA9B38434
Cylance Unsafe
Sangfor Malware
BitDefender Gen:Variant.DarkHotel.31
Cybereason malicious.384346
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Agent-ASKW [Trj]
GData Gen:Variant.DarkHotel.31
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Generic.ee20a163
Paloalto generic.ml
Tencent Win32.Trojan.Darkhotel.Sxof
Ad-Aware Gen:Variant.DarkHotel.31
Emsisoft Gen:Variant.DarkHotel.31 (B)
DrWeb Trojan.Click3.20117
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
FireEye Generic.mg.c47da9b3843466df
Ikarus Win32.Outbreak
Endgame malicious (high confidence)
Arcabit Trojan.DarkHotel.31
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.D!ml
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34084.dmW@aq27bOj
ALYac Gen:Variant.DarkHotel.31
MAX malware (ai score=88)
VBA32 suspected of Backdoor.PcClient.2
ESET-NOD32 a variant of Win32/TrojanProxy.Agent.NJK
Rising Trojan.Proxy-Agent!8.16D (CLOUD)
SentinelOne DFI – Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Agent.NJK!tr
AVG Win32:Agent-ASKW [Trj]
CrowdStrike win/malicious_confidence_90% (W)

How to remove DarkHotel.31?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.406487220 malicious file

The Malware.AI.406487220 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Trojan.PWS.OnlineGames.KDXA information

The Trojan.PWS.OnlineGames.KDXA is considered dangerous by lots of security experts. When this infection is active,…

46 mins ago

Trojan:Win32/Koutodoor!pz removal tips

The Trojan:Win32/Koutodoor!pz is considered dangerous by lots of security experts. When this infection is active,…

46 mins ago

About “Trojan:Win32/Regrun!pz” infection

The Trojan:Win32/Regrun!pz is considered dangerous by lots of security experts. When this infection is active,…

48 mins ago

What is “Malware.AI.3739112771”?

The Malware.AI.3739112771 is considered dangerous by lots of security experts. When this infection is active,…

53 mins ago

Generic.MSIL.Bladabindi.574A3861 (file analysis)

The Generic.MSIL.Bladabindi.574A3861 is considered dangerous by lots of security experts. When this infection is active,…

57 mins ago