Trojan

Trojan.Generic.31218028 removal instruction

Malware Removal

The Trojan.Generic.31218028 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31218028 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

Related domains:

incoming.telemetry.mozilla.org
aus5.mozilla.org

How to determine Trojan.Generic.31218028?


File Info:

name: BDEBE5B8D39C78AA0204.mlw
path: /opt/CAPEv2/storage/binaries/cb8f899319b411c46b7edc839a1dd6383f9125d3f675b637a7ce0c3018ad4133
crc32: 6527A0E9
md5: bdebe5b8d39c78aa020487f85b69e400
sha1: 49193200cf41a4dad7443baf887d513c740528f8
sha256: cb8f899319b411c46b7edc839a1dd6383f9125d3f675b637a7ce0c3018ad4133
sha512: 21637ad2c3a66e94cca8edf68dc9b21740397aebab69947b8c279ff620d4febd9a1170473ea01b057086521050f9c1cf4b482e18b07d738731fab8bf9972b8cd
ssdeep: 3072:M733U+Oz1nUxfJjXOE8Q04+D7jYgivWovTi2:2hOz1nUjjeE8ldiR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194F3BE1136E0C072D9F75A3025B0CBA15A7BBC726A7154CB67A8362E1F307DC4AB8797
sha3_384: 744290437ecc72872188867871b4103f5d8f61aa1d54c2a070c28bb2e1f6e7aab1555e50335d9aac584af395ff7b91ba
ep_bytes: e8d02a0000e989feffff8bff558bec68
timestamp: 2021-05-26 12:17:00

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Trojan.Generic.31218028 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
McAfeePacked-GEE!BDEBE5B8D39C
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/GenKryptik.015537ae
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0cf41a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKH
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.Generic.31218028
ViRobotTrojan.Win32.Z.Agent.158208.AAN
MicroWorld-eScanTrojan.Generic.31218028
AvastWin32:CrypterX-gen [Trj]
Ad-AwareTrojan.Generic.31218028
SophosMal/Agent-AWV
DrWebTrojan.Siggen15.50178
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
FireEyeGeneric.mg.bdebe5b8d39c78aa
IkarusTrojan-Ransom.StopCrypt
AviraTR/AD.MalwareCrypter.pjrlf
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Fareit.FTR!MTB
GDataWin32.Trojan-Downloader.SmokeLoader.L5XEQL
AhnLab-V3CoinMiner/Win.Glupteba.R452303
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.jq0@aysWySjI
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002H06KM21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.FNWP!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.31218028?

Trojan.Generic.31218028 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment