Trojan

About “Trojan.Generic.30311820” infection

Malware Removal

The Trojan.Generic.30311820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.30311820 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Generic.30311820?


File Info:

name: D1056EF913E91E8B7A45.mlw
path: /opt/CAPEv2/storage/binaries/9e99f9018c8473401505da1ce287ef817eaf0f0909195baca94cad8bbb699ee1
crc32: 5BD938B8
md5: d1056ef913e91e8b7a4532b33e051639
sha1: 3ee81be8aa877e6699614892fd1038b99c4a2181
sha256: 9e99f9018c8473401505da1ce287ef817eaf0f0909195baca94cad8bbb699ee1
sha512: 66244b6efb3c5fabc87f89edb07af9a11c5305ce9c3c29e666a79503a173084c90ea072d6e3a4cf813d07474aad892cc18859841aff12610d77773fec26ce834
ssdeep: 12288:aLbchyepcjYrV3bjriMUc0Jq7EQ9P0oVPig264r8jaej0xWYR0TfqnUgnJp0lUrY:ebgyibj2tZobs0f2H2j0xWYRT0lUjB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10F053390CB2068CCF6BF35BD181921D6B9D21D394636CDE4D8DFAA770CA4601FF81669
sha3_384: 05dafc61568181613e9d455b639d260c3e5b7dcb03eca08f658240df1800b32207a0a42fdecc3ac8f2088f48a7918472
ep_bytes: 83ec04c70424000000008b042483c404
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Generic.30311820 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.30311820
FireEyeGeneric.mg.d1056ef913e91e8b
McAfeeGenericRXAA-AA!D1056EF913E9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.8aa877
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Copak
BitDefenderTrojan.Generic.30311820
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosML/PE-A + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftTrojan.Generic.30311820 (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitCoinMiner.wmh
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Kryptik.ffp
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataTrojan.Generic.30311820
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4303164
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aaFtWfg
ALYacTrojan.Generic.30311820
MAXmalware (ai score=83)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
RisingTrojan.Injector!1.C865 (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.74654884.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.Generic.30311820?

Trojan.Generic.30311820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment