Trojan

Trojan.Generic.31358773 malicious file

Malware Removal

The Trojan.Generic.31358773 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31358773 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Divehi
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.Generic.31358773?


File Info:

name: 11DEFEFB12686B69083C.mlw
path: /opt/CAPEv2/storage/binaries/f0919fbe2dd00992504149f0ee82db211e1adbfdda331eb1118851e39e23fd63
crc32: 46C93E43
md5: 11defefb12686b69083cfe65c0a1f70d
sha1: 8457a7d5ffa4559dee9837185f95e865c48570f1
sha256: f0919fbe2dd00992504149f0ee82db211e1adbfdda331eb1118851e39e23fd63
sha512: fa06a0f5a05bc8a5245dc4509e0c646bed1f8ad556efd6d1259e6f3282d2efb620a42a75659a6622e3d289f321bae8dc99b68a84945baf3c86d80e2f9fd8b381
ssdeep: 6144:3QfzS9Gx3PbVemVkuzq07h4hvdJeLAlPSLW:gfzS9Gx3PbVeckuzj7h4hv6LAaW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114747D10B7A0C035F5B316F849B9A275B52E7EE16B2890CB53D52BEE96396D0EC30347
sha3_384: 5a974725a30da5c7c91dd71c474af076e23246f8ed3cf78a8d86cbdbcb43a4ce467c94926e1a340147c8546f14d4b221
ep_bytes: 8bff558bece876b10000e8110000005d
timestamp: 2020-07-08 22:34:53

Version Info:

0: [No Data]

Trojan.Generic.31358773 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31358773
FireEyeGeneric.mg.11defefb12686b69
ALYacTrojan.Generic.31358773
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Raccrypt.fe0441d1
K7GWTrojan ( 0058c6f11 )
K7AntiVirusTrojan ( 0058c6f11 )
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNVS
BaiduWin32.Trojan.Kryptik.jm
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBL5Z
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9918587-0
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderTrojan.Generic.31358773
AvastWin32:Trojan-gen
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.Generic.31358773
SophosMal/Generic-S
DrWebTrojan.Siggen16.22933
TrendMicroTrojan.Win32.SMOKELOADER.YXBL5Z
McAfee-GW-EditionBehavesLike.Win32.Packed.fm
EmsisoftTrojan.Generic.31358773 (B)
APEXMalicious
GDataWin32.Trojan.BSE.554AXK
AviraTR/Kryptik.yftns
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Raccrypt.GW!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R461694
Acronissuspicious
McAfeePacked-GEE!11DEFEFB1268
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.FL
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure!1.A3BB (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HNVQ!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.5ffa45
PandaTrj/GdSda.A

How to remove Trojan.Generic.31358773?

Trojan.Generic.31358773 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment