Trojan

Trojan.Generic.31218264 removal tips

Malware Removal

The Trojan.Generic.31218264 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31218264 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

Related domains:

wpad.local-net

How to determine Trojan.Generic.31218264?


File Info:

name: F2A73C0BA1258C2FAB80.mlw
path: /opt/CAPEv2/storage/binaries/0bc0a84603b942332a2342441604fba9e346c26caa6f3d49dbd9d12efb03ab7b
crc32: 90A9A8E3
md5: f2a73c0ba1258c2fab80317a97f7d231
sha1: 7a0bc65c01e43b83e70075402f311a159bb34b95
sha256: 0bc0a84603b942332a2342441604fba9e346c26caa6f3d49dbd9d12efb03ab7b
sha512: 58761efb98a637411a45c65a0fc8953a6ae09f9c3b0ac265dc614d8984e49efadefce50248f612ec3b98499cf36def74506414495680555282c87d236b2c6f10
ssdeep: 49152:yt5qUxJGAN8XxuueISVKZhkMGd19hoNojsUqQDYZggRROe415as1:yfqUCa8XxuIjkMA19hoNoFD2ggOe
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T144B533DCE5A09F30F9D135F9B8D2F19A84CBEAC936DA01970390313792D7324A9DA51B
sha3_384: 72cc3718c76804bc587f36c2421aa42058d89e07066f9ab988f553307822b68d0967ed76ba53113b881b4ceca7e058b2
ep_bytes: ba0000000083ec04890c2481c7db0270
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Generic.31218264 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanTrojan.Generic.31218264
FireEyeGeneric.mg.f2a73c0ba1258c2f
ALYacTrojan.Generic.31218264
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
K7AntiVirusTrojan ( 0057ffc71 )
BitDefenderThetaGen:NN.ZexaF.34294.toZ@aOKLpMd
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
TrendMicro-HouseCallTROJ_GEN.R002C0DKN21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.kxiw
BitDefenderTrojan.Generic.31218264
AvastWin32:CoinminerX-gen [Trj]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareTrojan.Generic.31218264
EmsisoftTrojan.Generic.31218264 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Kryptik.Win32.3625563
TrendMicroTROJ_GEN.R002C0DKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-R
IkarusTrojan.Win32.Injector
GDataTrojan.Generic.31218264
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.C690
ViRobotTrojan.Win32.Z.Zusy.2409984.BDZ
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R369407
McAfeeGenericRXAA-FA!F2A73C0BA125
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
APEXMalicious
TencentTrojan.Win32.Coinminer.yi
YandexTrojan.Copak!X9CqF9bMOn4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.ba1258
PandaTrj/Genetic.gen

How to remove Trojan.Generic.31218264?

Trojan.Generic.31218264 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment