Trojan

Trojan.Generic.31103347 removal tips

Malware Removal

The Trojan.Generic.31103347 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31103347 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Behavioural detection: Transacted Hollowing
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Attempts to execute suspicious powershell command arguments
  • Powershell arguments were seen on a command line but powershell.exe was not called. Likely indictive of renamed/obfuscated powershell.exe or defining arguments in variables for later use
  • Collects information to fingerprint the system

How to determine Trojan.Generic.31103347?


File Info:

name: 8E246E2F994E59011799.mlw
path: /opt/CAPEv2/storage/binaries/ca17c1cb1d6fe4a3e7f22a3dfc637e7aac39f8d5d7e70d9e17e4306f1dd1362f
crc32: 5497A1B5
md5: 8e246e2f994e59011799a046fc4ecd97
sha1: 2f3f12c325b19289cd56f61f1598b69001598928
sha256: ca17c1cb1d6fe4a3e7f22a3dfc637e7aac39f8d5d7e70d9e17e4306f1dd1362f
sha512: 6ca2f220071f97b801cf20dd3cf432fa78f7c9d927e6b17b2f0ffad2ff719c3753224f6e2b4d16ac953a1184fb4098630b5a8ad62b35097e689d828516ded3d7
ssdeep: 98304:d90PbbHgUQTLFwHImICoT7uHv+3xG27MbslC2u3:SbbHCm87uHvkzlG3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CF58C30768BC53BD56209B16A2CDBAF51287F650F7294C763D81E6E88B48C39731E27
sha3_384: a9b81151266582b0ab39f8dd3f1a314ff19d054ae3f6ba6df17a7b1c4d9e51d1b5d786080f38b5569d7a4351f741a1fb
ep_bytes: e885060000e97afeffffcccccccccccc
timestamp: 2021-05-24 16:18:27

Version Info:

CompanyName: Common Apps
FileDescription: AmongUs-Installer Installer
FileVersion: 1.3.5
InternalName: AmongUs-Installer
LegalCopyright: Copyright (C) 2021 Common Apps
OriginalFileName: AmongUs-Installer.exe
ProductName: AmongUs-Installer
ProductVersion: 1.3.5
Translation: 0x0409 0x04b0

Trojan.Generic.31103347 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Miner.a!c
MicroWorld-eScanTrojan.Generic.31103347
ClamAVWin.File.Alien-9935129-0
McAfeeGenericRXAA-FA!8E246E2F994E
CylanceUnsafe
SangforSuspicious.Win32.Malware.gen
K7AntiVirusUnwanted-Program ( 005809781 )
K7GWUnwanted-Program ( 005809781 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32PowerShell/Disabler.B potentially unsafe
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Downloader.Win32.Miner.gen
BitDefenderTrojan.Generic.31103347
AvastWin32:Malware-gen
TencentWin32.Trojan.FalseSign.Jcnw
Ad-AwareTrojan.Generic.31103347
EmsisoftTrojan.Generic.31103347 (B)
VIPRETrojan.Generic.31103347
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8e246e2f994e5901
SophosGeneric PUA CP (PUA)
IkarusPUA.PowerShell.Disabler
GDataTrojan.Generic.31103347
AviraHEUR/AGEN.1223728
ArcabitTrojan.Generic.D1DA9973
ZoneAlarmHEUR:Trojan-Downloader.Win32.Miner.gen
MicrosoftPUA:Win32/Bitrepeyp.B
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R446001
Acronissuspicious
ALYacTrojan.Generic.31103347
MAXmalware (ai score=87)
MalwarebytesRiskWare.Disabler
RisingDownloader.Miner!8.1A26 (CLOUD)
MaxSecureTrojan.Malware.74205151.susgen
FortinetAdware/Disabler
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Generic.31103347?

Trojan.Generic.31103347 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment