Trojan

How to remove “Trojan.Generic.31289592”?

Malware Removal

The Trojan.Generic.31289592 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31289592 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:43958
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Generic.31289592?


File Info:

name: 50574CE8D4B5DBF27F9E.mlw
path: /opt/CAPEv2/storage/binaries/cd4fdc6d1cc85621ccc691f43a7ec248c6d854fdbba3ea6920d06a35231b9c8d
crc32: A6DB6AE7
md5: 50574ce8d4b5dbf27f9e775e2f0479bf
sha1: b23f0e3655b359458c8dbfb24a5091d586b9187c
sha256: cd4fdc6d1cc85621ccc691f43a7ec248c6d854fdbba3ea6920d06a35231b9c8d
sha512: 8589d781c8b6367b658cb80459aee226f2377527c514d4705bb31590d8c4311bfc51afc8d07b17ab79856a9d40034a500103a3a8ac2810eb6f2fa5bf73524860
ssdeep: 12288:sZmXMBoD1rgfp3hdZ15DnDbHCiLKNdpEc5PGHhu05yyQr:swXyoD6p3hdZHDDdLKWcwBQr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1A423FB199A05ACC1970AB4B76D41286B0D9B36F04E772B8757372AC4DF924FAB1018
sha3_384: 659cf046cc179ae38a667eb37658575c1700f05ff62e1e322bfcb1fc3f154db8ed86f12d18718c05e027d8678173a443
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2001-05-29 14:03:50

Version Info:

0: [No Data]

Trojan.Generic.31289592 also known as:

MicroWorld-eScanTrojan.Generic.31289592
FireEyeTrojan.Generic.31289592
ALYacTrojan.Generic.31289592
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.35987
SangforHacktool.Win32.Serv-U.3017
K7AntiVirusTrojan ( 00002ea51 )
K7GWTrojan ( 00002ea51 )
CyrenW32/Tool.SYXN-8111
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ServU-Daemon potentially unsafe
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Servu-22
Kasperskynot-a-virus:Server-FTP.Win32.Serv-U.3017
BitDefenderTrojan.Generic.31289592
NANO-AntivirusTrojan.Win32.Servu.fiixgq
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.31289592
SophosTroj/Servu-AB
ComodoApplicUnsaf.Win32.ServU-Daemon.~S3@hxgv3
DrWebBackDoor.Servu.30
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03BC0PLL21
EmsisoftTrojan.Generic.31289592 (B)
IkarusBackdoor.IRC.Cloner
GDataTrojan.Generic.31289592
JiangminBackdoor/ServU-based.b
WebrootW32.Trojan.Gen
AviraTR/HK.3
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.201B3
GridinsoftRansom.Win32.Wacatac.sa
ViRobotBackdoor.Win32.ServU.490496
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Unwanted/Win32.Serv.R75571
McAfeeServU-Daemon.aj
VBA32Backdoor.ServUbased
TrendMicro-HouseCallTROJ_GEN.R03BC0PLL21
RisingBackdoor.Win32.Servudoor.d (CLASSIC)
YandexTrojan.GenAsa!6d6eR6DNI5E
eGambitUnsafe.AI_Score_50%
FortinetW32/ServUBased.A!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34114.DOWbaynkm7ei
AVGWin32:Malware-gen
PandaBck/ServU.BY
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Generic.31289592?

Trojan.Generic.31289592 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment