Trojan

Trojan.Generic.31219365 information

Malware Removal

The Trojan.Generic.31219365 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31219365 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Generic.31219365?


File Info:

name: B6E4AA442979CC518CE5.mlw
path: /opt/CAPEv2/storage/binaries/358d9126a5f446dd9d8ce536a1c4d8ee342a8a1aab7e815d729f9049f47d81c5
crc32: BB55FAE2
md5: b6e4aa442979cc518ce5aadcc9529893
sha1: 6eb43693a03362795773ed204eddfe0e348ac9a0
sha256: 358d9126a5f446dd9d8ce536a1c4d8ee342a8a1aab7e815d729f9049f47d81c5
sha512: 08d47cfdce7f509556289274557eacf9d44fb2785bb227c6f3509756a7e67f84c87efc5f59a0fac09c8393c29bcc6ee3d5857ed9db883fe79e34bfa501f58c82
ssdeep: 12288:v+bK4Z+8EAsu851K3x1qIBdo+XPQrnAOPINNNn7hyYAUoyeqeZk7CBWjINAtpxTf:miNAsL1KSIBjSPINvn0vGey2BWjVxzgW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192F42353CAB240E6F2FAD4B4B13740928A066887582537F95CE4E79614F36E3F7E1827
sha3_384: f3b6cf5e45b650f9271d7011cad00b66a23acd7a9896ad63157af5b00fa5d46e9046f2e4691fa1bef0d49c0c148eccc3
ep_bytes: 60be00e047008dbe0030f8ff57eb0b90
timestamp: 2021-08-18 05:52:34

Version Info:

FileVersion: 2.0.1.193
Comments: 更新浏览器配置文件
FileDescription: Eclipse Portable
ProductVersion: 0.0.0.0
Translation: 0x0804 0x04b0

Trojan.Generic.31219365 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoader9.710
MicroWorld-eScanTrojan.Generic.31219365
FireEyeGeneric.mg.b6e4aa442979cc51
McAfeeArtemis!B6E4AA442979
CylanceUnsafe
ZillyaDropper.Demp.Win32.2898
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDropper:Win32/Generic.0884929d
K7GWRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WKQ21
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-6651422-0
KasperskyTrojan-Dropper.Win32.Demp.ayal
BitDefenderTrojan.Generic.31219365
AvastWin32:Malware-gen
TencentWin32.Trojan-dropper.Demp.Phzw
Ad-AwareTrojan.Generic.31219365
SophosGeneric ML PUA (PUA)
TrendMicroTROJ_GEN.R002C0WKQ21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bc
EmsisoftTrojan.Generic.31219365 (B)
GDataTrojan.Generic.31219365
JiangminTrojan/Agent.hqzz
AviraTR/Drop.Demp.nmpnu
MAXmalware (ai score=83)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32TrojanDropper.Demp
ALYacTrojan.Generic.31219365
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazqANSMd6Rem9ef14vHIFqfa)
eGambitUnsafe.AI_Score_100%
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Cybereasonmalicious.3a0336

How to remove Trojan.Generic.31219365?

Trojan.Generic.31219365 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment