Trojan

Trojan.Generic.31354796 removal instruction

Malware Removal

The Trojan.Generic.31354796 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31354796 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Generic.31354796?


File Info:

name: FD0EEA5952BB5382D9F8.mlw
path: /opt/CAPEv2/storage/binaries/71f58ff469163a555ca3d40f961651656c2eb6ccec25d082a33f7daa12ba26d4
crc32: 2A022B76
md5: fd0eea5952bb5382d9f8463873676d05
sha1: 1c225b5383e600a80bf65bacf62d04799f17ebfc
sha256: 71f58ff469163a555ca3d40f961651656c2eb6ccec25d082a33f7daa12ba26d4
sha512: eca8ba111160c477fb01e73d50c4c858b10fce3e93d34f937ebd50ecd0fbd940faee000c8d080d00bc461c7a289df0db0c22969067a99297c0466b3d8f0cecc9
ssdeep: 12288:phPjIVvBMcbvXQE9wbaNVQGWcQl+rtVseHHl9OmDr/zxBUWL5l1fYYg+QBf39T:pZIVvZQESuNVQGWcQCf/VBUElSNt39T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFA56F9CD18094A1E40E16F175364CD1081A6E64D63441DE3FFEBE2E5AB32922CB6FDB
sha3_384: 32f1aa759581d6a3918778842ffb6b28ee1270ea6b5c806ab730175e2a758fa951b9e7e310037d24eb7ea459341e9043
ep_bytes: e86e060000e98efeffff558bec6a00ff
timestamp: 2020-11-05 09:54:29

Version Info:

CompanyName: 淮安成思科技有限公司
FileDescription: 七彩WiFi
InternalName: 七彩WiFi
LegalCopyright: Copyright (C) 2020
OriginalFilename: ColorfulBst.exe
ProductName: 七彩WiFi
ProductVersion: 1,0,2,21105
Translation: 0x0804 0x04b0

Trojan.Generic.31354796 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Softcnapp.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31354796
FireEyeGeneric.mg.fd0eea5952bb5382
ALYacTrojan.Generic.31354796
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.bh
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 00570d6e1 )
K7AntiVirusAdware ( 00570d6e1 )
BitDefenderThetaGen:NN.ZexaF.34114.@D2@aG8EeNcj
VirITWin32.Sality.BI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BG potentially unwanted
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.Generic.31354796
NANO-AntivirusRiskware.Win32.Softcnapp.icyuvx
AvastWin32:Sality [Inf]
RisingAdware.Agent!1.C6F0 (CLOUD)
Ad-AwareTrojan.Generic.31354796
SophosGeneric PUA BM (PUA)
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroTROJ_GEN.R002C0PKI21
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
EmsisoftTrojan.Generic.31354796 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Ren.Gen
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
ViRobotAdware.Softcnapp.2082672.B
GDataTrojan.Generic.31354796
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!FD0EEA5952BB
MAXmalware (ai score=81)
VBA32BScope.Adware.Softcnapp
MalwarebytesPUP.Optional.Softcnapp
TrendMicro-HouseCallTROJ_GEN.R002C0PKI21
TencentPua:Adware.Win32.Softcnapp.16000025
YandexRiskware.Agent!jBEgBQn6G4g
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Softcnapp.BC
AVGWin32:Sality [Inf]

How to remove Trojan.Generic.31354796?

Trojan.Generic.31354796 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment