Trojan

Trojan.Generic.31217995 malicious file

Malware Removal

The Trojan.Generic.31217995 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31217995 virus can do?

  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
meron.kanoga-apps.com

How to determine Trojan.Generic.31217995?


File Info:

name: 6BBA8AAEE6EC8B55FFC1.mlw
path: /opt/CAPEv2/storage/binaries/fbb55a284950b6b68cd6bf22d6085f9c39c0460b2a9c9e7dee9e2adafb38fa8b
crc32: 8152BA1E
md5: 6bba8aaee6ec8b55ffc1ab1b75ab669e
sha1: 061072d78935976f7770fe69405f7aef4bcbf407
sha256: fbb55a284950b6b68cd6bf22d6085f9c39c0460b2a9c9e7dee9e2adafb38fa8b
sha512: 4c58d53c3aad495a81322c9470e3bfc680f55c4900a101c96c4720b64c1b918152a4a1657bfcc88d812009e2c4b3e16a4a31a1036a91718d7d5a651a76bb6e4e
ssdeep: 1536:W04f1SMHjZ0k/tB1g//I0DuoxbxAHscqklHE91EirFmGbxXZTa8rq5yZ:of1BDZ0kVB67Duw9AMcqkq1RrFtxJ0yZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160649F92AA10D9D7FF66073115797BDA9B51AD2E63C0C61F93047EB068732832A3E543
sha3_384: 01dcfb83967ef0f78e6009f0539c39280b5b23dc9bbe7581724bb46d0a51bcc451cb34aaaeaa2a2120e7aac50ce76994
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2020-08-01 02:44:50

Version Info:

FileVersion: 1.7.27.974
ProductVersion: 1.7.11.437
Translation: 0x0409 0x04e4

Trojan.Generic.31217995 also known as:

LionicTrojan.Win32.Adload.a!c
MicroWorld-eScanTrojan.Generic.31217995
FireEyeTrojan.Generic.31217995
ALYacTrojan.Generic.31217995
ZillyaDownloader.Adload.Win32.112397
K7AntiVirusTrojan-Downloader ( 0058ab1f1 )
AlibabaAdWare:Win32/AdLoad.89c791e4
K7GWTrojan-Downloader ( 0058ab1f1 )
CyrenW32/Adload.GF.gen!Eldorado
ESET-NOD32NSIS/TrojanDownloader.Agent.NZR
APEXMalicious
AvastNSIS:DropperX-gen [Drp]
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.Generic.31217995
TencentNsis.Trojan-downloader.Agent.Wsas
Ad-AwareTrojan.Generic.31217995
DrWebAdware.Downware.20015
TrendMicroTROJ_GEN.R06CC0PKQ21
EmsisoftTrojan.Generic.31217995 (B)
AviraTR/Dldr.Agent.dozzu
GridinsoftRansom.Win32.Wacatac.sa
GDataTrojan.Generic.31217995
CynetMalicious (score: 99)
AhnLab-V3Dropper/Win.DropperX-gen.C4785887
VBA32suspected of Trojan.Downloader.gen
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_GEN.R06CC0PKQ21
FortinetNSIS/Agent.NZR!tr.dldr
AVGNSIS:DropperX-gen [Drp]
PandaTrj/CI.A

How to remove Trojan.Generic.31217995?

Trojan.Generic.31217995 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment