Trojan

About “Trojan.Generic.31222119” infection

Malware Removal

The Trojan.Generic.31222119 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31222119 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Generic.31222119?


File Info:

name: 5CB2282A2C618C4BC88B.mlw
path: /opt/CAPEv2/storage/binaries/402b0a019bafa68836e3c9b0ce5dd5ea09e8de4b77e2d2600587092929935fd5
crc32: 7B111210
md5: 5cb2282a2c618c4bc88bf80263d4a07c
sha1: 8846ee913c1a74a4ac4bd8165590578ebe210b95
sha256: 402b0a019bafa68836e3c9b0ce5dd5ea09e8de4b77e2d2600587092929935fd5
sha512: 4f7084c72065bdcc185539bd7b06615a4cf0bafbee22c934e5e1546cc97ae2d17c14b4ff53eed97937846184a8c7bad14dd5acc1be6c299b850a8b5e0cedf8ad
ssdeep: 6144:U2ZK/jWRmaQUFOhuduzbgwu6L7ITsqSigaTwVf:NZKCRmaQphudunnn7s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190449DF076D8CC71D0932E3044609AA40A3BBC51D5609547F7B4A79E2EB3BCCA6E635E
sha3_384: b81c51c482ba38f6ec34a61d27b60cfa98d804185665644791a52041f03c763318a9a00a8c0ea78261b600a7cb49006a
ep_bytes: e854420000e989feffff6a086870b041
timestamp: 2020-08-14 07:38:45

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkagat
ProductVersion: 15.54.12.11
Translation: 0x0014 0x046a

Trojan.Generic.31222119 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31222119
FireEyeGeneric.mg.5cb2282a2c618c4b
ALYacTrojan.Generic.31222119
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058bf181 )
AlibabaRansom:Win32/StopCrypt.e7c283e1
K7GWTrojan ( 0058bf181 )
Cybereasonmalicious.13c1a7
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNFO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9906674-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.Generic.31222119
NANO-AntivirusTrojan.Win32.Kryptik.jhcefh
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:MalwareX-gen [Trj]
TencentTrojan-Spy.Win32.Stealer.16000121
Ad-AwareTrojan.Generic.31222119
EmsisoftTrojan.Crypt (A)
DrWebTrojan.Siggen15.36481
TrendMicroTrojan.Win32.SMOKELOADER.YXBKHZ
McAfee-GW-EditionBehavesLike.Win32.Worm.dh
SophosMal/Generic-R + Troj/Krypt-BO
IkarusTrojan-Ransom.StopCrypt
GDataTrojan.Generic.31222119
JiangminTrojan.Agent.drao
AviraHEUR/AGEN.1136028
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D1DC6967
MicrosoftRansom:Win32/StopCrypt.PS!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.OC.R449108
Acronissuspicious
McAfeeLockbit-FSWW!5CB2282A2C61
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBKHZ
RisingTrojan.DiskWriter!8.87FB (TFE:5:zYN66UgGDbD)
YandexTrojan.Agent!yjFIbdQVBqE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34114.qq0@amcI34nI
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.31222119?

Trojan.Generic.31222119 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment