Trojan

About “Trojan.Generic.31207448” infection

Malware Removal

The Trojan.Generic.31207448 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31207448 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

www.baidu.com
down4.7654.com
domain.thorzip.muxin.fun
castle.shzhanmeng.com
ssp.7654.com
mininews-hn.7654.com
tips-hn.7654.com
report.uchiha.ltd
news.7654.com

How to determine Trojan.Generic.31207448?


File Info:

crc32: 030AA946
md5: 806a8400278c5ac84002b71e7b16385a
name: 806A8400278C5AC84002B71E7B16385A.mlw
sha1: a61e7e0f9ece8fd0e52d49c878fe8a1a6127bc0f
sha256: 1bfd3c8e6977a8f88fc40de618e175bab6fe4a9371a73df016a568c54ea24dbc
sha512: a939b15c400ff7f30a36bd196ce44dbcc76ad1b72b0f747a2e40c08e16a40f897e7420b56d65f3b4969795ded3e03bf341a5cb82f16f05e5d4fa89f626235a87
ssdeep: 24576:Z3rskPbNxm0TDWvknxNcKi2Mc/DDC8XlLmtYm+PPW6JQoSws+Opv5sh3y4aJM8dz:RPhxm0PWvt8oUWkQTneKoDcTTfjZospt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2019 x4e0ax6d77x5c55x76dfx7f51x7edcx79d1x6280x6709x9650x516cx53f8 All Rights Reserved
InternalName: upgrade.exe
FileVersion: 3.3.0.2
CompanyName: x4e0ax6d77x5c55x76dfx7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: upgrade.exe
ProductVersion: 3.3.0.2
FileDescription: upgrade.exe
OriginalFilename: upgrade.exe
Translation: 0x0804 0x04b0

Trojan.Generic.31207448 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00565ab71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.13229
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.KuziTui.Win32.1715
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/KuaiZip.a6a00f9f
K7GWAdware ( 00565ab71 )
Cybereasonmalicious.f9ece8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KuaiZip.AB potentially unwanted
APEXMalicious
AvastWin32:Sality [Inf]
Kasperskynot-a-virus:UDS:AdWare.Win32.KuziTui.gen
BitDefenderTrojan.Generic.31207448
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanTrojan.Generic.31207448
TencentPua:Adware.Win32.Kuzitui.16000040
Ad-AwareTrojan.Generic.31207448
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34294.yD2@a0J2iDij
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.806a8400278c5ac8
EmsisoftTrojan.Generic.31207448 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.KuziTui.abo
AviraTR/Patched.Ren.Gen
eGambitUnsafe.AI_Score_66%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.Generic.31207448
Acronissuspicious
McAfeeGenericRXAA-AA!806A8400278C
MAXmalware (ai score=87)
VBA32BScope.Adware.Burden
MalwarebytesPUP.Optional.Kuaizip
TrendMicro-HouseCallPE_SALITY.ER
RisingAdware.Agent!1.C6CF (CLASSIC)
YandexPUA.KuziTui!Y2QXghY/CEM
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/KuaiZip.AB
AVGWin32:Sality [Inf]
Paloaltogeneric.ml

How to remove Trojan.Generic.31207448?

Trojan.Generic.31207448 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment