Trojan

Trojan.Generic.31217911 removal tips

Malware Removal

The Trojan.Generic.31217911 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31217911 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Generic.31217911?


File Info:

name: 8725C434202CFFC9EC8C.mlw
path: /opt/CAPEv2/storage/binaries/da4ac10d92d86861bd20bbbec4aad628451f654092319ef5ed2fc4be13b984d9
crc32: D8304BF3
md5: 8725c434202cffc9ec8c0183971340ae
sha1: d1cd4538f02f6e2b570a5c51b3b63520a7afd37c
sha256: da4ac10d92d86861bd20bbbec4aad628451f654092319ef5ed2fc4be13b984d9
sha512: 8c4918530b8daf291c7a8f813a46b2a715891beee56bd6f82538c2161d56de84854024ad65f4c85bfa06a9121316c6563747665ff1c3638657d3b961a6cf90c4
ssdeep: 3072:X733U+Oz1nUU+vVW3wzhTRWOrK+17gV+QVLy3wYm2:bhOz1nUUgW3kRWOxsal
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178F3BE213AE1E0B2D8F7253035708BA11B7AB972A672454F7F68253E0F707D04AB9767
sha3_384: 95f9066a0c5d756c09625021aced04451eccc5e3c2b5de560b807c198081ef573d5e3d51cd61393620f749734724d2b1
ep_bytes: e8d02a0000e989feffff8bff558bec68
timestamp: 2020-10-28 15:47:14

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Trojan.Generic.31217911 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31217911
FireEyeGeneric.mg.8725c434202cffc9
McAfeeLockbit-FSWW!8725C434202C
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Mokes.1a35a15e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8f02f6
CyrenW32/StopCrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKH
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Mokes.anxv
BitDefenderTrojan.Generic.31217911
AvastWin32:CrypterX-gen [Trj]
Ad-AwareTrojan.Generic.31217911
SophosMal/Agent-AWV
DrWebTrojan.Siggen15.50178
TrendMicroTrojan.Win32.SMOKELOADER.YXBKXZ
McAfee-GW-EditionBehavesLike.Win32.Lockbit.ch
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.11GYDBI
JiangminTrojan.Agent.dsav
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.MalwareCrypter.ijlvy
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34D6456
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.STOP.sa
ArcabitTrojan.Generic.D1DC58F7
ViRobotTrojan.Win32.Z.Agent.158208.AAO
MicrosoftTrojan:Win32/Azorult.RT!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R452303
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.jq0@aKADv1gI
ALYacTrojan.Generic.31217911
VBA32Trojan.Agent
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBKXZ
RisingTrojan.Kryptik!1.DAC3 (CLASSIC)
YandexBackdoor.Mokes!/9yoh5eCHdw
IkarusTrojan-Ransom.StopCrypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Packed.GEE!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.31217911?

Trojan.Generic.31217911 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment