Trojan

Trojan.Generic.31251980 malicious file

Malware Removal

The Trojan.Generic.31251980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31251980 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Colombia)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.Generic.31251980?


File Info:

name: AD851ED9E89DA8C21D27.mlw
path: /opt/CAPEv2/storage/binaries/b616250c13a667a3a0c404f3e66bc160767daf92d85dc82716a092ef5ed5cb35
crc32: 35103809
md5: ad851ed9e89da8c21d2712082fc34bb0
sha1: 559f300df58363c88db1d465b7581aedb637a346
sha256: b616250c13a667a3a0c404f3e66bc160767daf92d85dc82716a092ef5ed5cb35
sha512: 74f28a022324aef36dde44bae6884a1f53dcba0b36660e845d27b50cb3f045976abdcbfa14c3e92cf17e84397ce71a18d270d3788507039956a74739be9ef124
ssdeep: 12288:Eg4XXrGbd4JjstR7zAm6A+fm6UJ1BuX4gEz:H4nr4cOR/HOP604gq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F094BF10E6A0D034F1B353F89AB9A369A52E7EA16B3490CF53D516EE57749E0EC3031B
sha3_384: 1024fd520b11a69e1bbf72f60849426df39afd771457c1e189f8ab6ebdf58a004d86c7607e664dea1648dbe30b17359f
ep_bytes: 8bff558bece856830000e8110000005d
timestamp: 2020-12-12 12:30:19

Version Info:

0: [No Data]

Trojan.Generic.31251980 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.31726
MicroWorld-eScanTrojan.Generic.31251980
FireEyeGeneric.mg.ad851ed9e89da8c2
McAfeePacked-GEE!AD851ED9E89D
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bd9341 )
AlibabaTrojanSpy:Win32/Azorult.b332f613
K7GWTrojan ( 0058b8681 )
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNPQ
TrendMicro-HouseCallTROJ_GEN.R03FC0DLA21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.Generic.31251980
AvastWin32:DropperX-gen [Drp]
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareTrojan.Generic.31251980
SophosMal/Generic-S
BaiduWin32.Trojan.Kryptik.jm
TrendMicroTROJ_GEN.R03FC0DLA21
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.anke
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.Agent.lcsbk
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34E92AC
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftMalware.Win32.GenericMC.cc
MicrosoftTrojan:Win32/Azorult.RW!MTB
ViRobotTrojan.Win32.Z.Stealer.439808.A
GDataWin32.Trojan.PSE.1G109FS
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.Generic.31251980
VBA32TrojanSpy.Stealer
MalwarebytesTrojan.MalPack.GS
APEXMalicious
IkarusTrojan.Win32
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.PALLAS.H
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Generic.31251980?

Trojan.Generic.31251980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment