Trojan

Trojan.Generic.31218363 removal tips

Malware Removal

The Trojan.Generic.31218363 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31218363 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Trojan.Generic.31218363?


File Info:

name: 91C48C96ABC11565FF61.mlw
path: /opt/CAPEv2/storage/binaries/d2eeb2e6a6058946a574873bb18b24431a5a28919c046dc0180260e187955c04
crc32: CD589C5E
md5: 91c48c96abc11565ff61eb6e850d71d1
sha1: ea3cdd0625b902d872cee1e70ab28c89b3a3f47f
sha256: d2eeb2e6a6058946a574873bb18b24431a5a28919c046dc0180260e187955c04
sha512: f1fa7aecd813d28b3c814859b907fc32eb540ed5641e1732f8ca57e694664d8a4a3e58e671fc33b85ec803a2dd3355152e26e264331e7b08385d413fae7629ce
ssdeep: 49152:1w80cTsjkWadn19Kgfg0tjB1+HqpWlfvYb:C8sjkt19FI0tjn+x2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BA5F12273DDC371CB669173BF2AB7016EBF38610630B95B2F981D7DA960161122D7A3
sha3_384: 5b6bb00ece7ce7f1330353ba406416c60de8fb8cf0f1c2fe7d25bee2293f0e8188daab0fea2a3a6752f68321c5c4ecb4
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2021-11-10 09:42:25

Version Info:

Translation: 0x0809 0x04b0

Trojan.Generic.31218363 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!e
MicroWorld-eScanTrojan.Generic.31218363
ALYacTrojan.Generic.31218363
K7AntiVirusTrojan ( 0056e5201 )
AlibabaTrojan:Win32/Predator.ali2000022
K7GWTrojan ( 0056e5201 )
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan.Win32.Autoit.acggn
BitDefenderTrojan.Generic.31218363
AvastAutoIt:Injector-U [Trj]
Ad-AwareTrojan.Generic.31218363
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WKP21
McAfee-GW-EditionArtemis
FireEyeTrojan.Generic.31218363
EmsisoftTrojan.Generic.31218363 (B)
IkarusTrojan.Win32.Injector
GDataWin32.Trojan.Agent.LNARXU
AviraTR/AutoIt.jdobu
ArcabitTrojan.Generic.D1DC5ABB
ViRobotTrojan.Win32.Z.Injector.2218656
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!91C48C96ABC1
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0WKP21
TencentWin32.Trojan.Autoit.Htls
eGambitUnsafe.AI_Score_70%
FortinetW32/Injector_Autoit.ANX!tr
AVGAutoIt:Injector-U [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.31218363?

Trojan.Generic.31218363 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment