Trojan

Trojan.Generic.31182108 removal instruction

Malware Removal

The Trojan.Generic.31182108 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31182108 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Generic.31182108?


File Info:

name: AE4B2E03870CF0F93AB5.mlw
path: /opt/CAPEv2/storage/binaries/356fe2f494efe1781e21b479104011bf33b6f2df09cda0541d6eb05771183048
crc32: AC775B9F
md5: ae4b2e03870cf0f93ab5d0030f2c5427
sha1: 3ce01791d57d3402cccba34699f8c8b9150bf605
sha256: 356fe2f494efe1781e21b479104011bf33b6f2df09cda0541d6eb05771183048
sha512: cc7ee6491f8d96433403e3a561f47c3412d193e60a44fbeb9c8897e046f0cf0a13eb7c1c214926d338344af580fed4429f25a55c9253e76713c41dad70c7aa58
ssdeep: 3072:AUApueDWSppTaeskDEjUrqfkZ557YzAL9gFoI3X3fZE5UANanP:ASeyGpTaesaQUufkL57YsL9NIx9ANaP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A444C213680C032E366273049E6E6F459A97D794AA4E64FF7B47F391E315938A3720F
sha3_384: 8af77041cd07e70de4f4ec606f451fb7ac25c1a9917980bdf817665a13d59e232b1406ef823fe20d6933c73bfec88829
ep_bytes: e8f4830000e979feffff8bff558bec8b
timestamp: 2014-07-02 12:38:36

Version Info:

0: [No Data]

Trojan.Generic.31182108 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31182108
FireEyeGeneric.mg.ae4b2e03870cf0f9
CAT-QuickHealBackdoor.PlitePMF.S22785952
ALYacTrojan.Generic.31182108
CylanceUnsafe
VIPRETrojan.Win32.Urelas.ab (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWBackdoor ( 0053e8561 )
K7AntiVirusBackdoor ( 0053e8561 )
BitDefenderThetaGen:NN.ZexaF.34294.qCX@a8TT4Omi
CyrenW32/Urelas.BB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.U
BaiduWin32.Trojan.Urelas.b
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
KasperskyBackdoor.Win32.Plite.bhtg
BitDefenderTrojan.Generic.31182108
NANO-AntivirusTrojan.Win32.Plite.fwxvjh
AvastWin32:Malware-gen
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.Generic.31182108
EmsisoftTrojan.Generic.31182108 (B)
ComodoTrojWare.Win32.Urelas.ASE@5izxb0
DrWebBackDoor.Golf.260
ZillyaBackdoor.Plite.Win32.4388
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosML/PE-A + Troj/Urelas-Q
SentinelOneStatic AI – Malicious PE
JiangminTrojan/GenericCryptor.bt
eGambitUnsafe.AI_Score_97%
AviraTR/Spy.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.2C48B8C
MicrosoftTrojan:Win32/Urelas.AA
GDataWin32.Trojan.PSE.1BSN4LX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Urelas.R439953
Acronissuspicious
McAfeePWS-FBQQ!AE4B2E03870C
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Gulf
MalwarebytesMalware.AI.847887156
RisingTrojan.Urelas!1.BE13 (CLASSIC)
YandexBackdoor.Plite!ezc9fa3vZWc
IkarusTrojan.Win32.Beaugrit
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Trojan.Generic.31182108?

Trojan.Generic.31182108 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment