Trojan

How to remove “Trojan.Generic.31388216”?

Malware Removal

The Trojan.Generic.31388216 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31388216 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Trojan.Generic.31388216?


File Info:

name: 053549C950AE1C2F103F.mlw
path: /opt/CAPEv2/storage/binaries/ca807ca0a962c0f7e2962a3daafce0c354d81b9b201df4caeecb6de28aaa15aa
crc32: F6B791E7
md5: 053549c950ae1c2f103f962dbec3d783
sha1: 729841de5c849fe4def7670caaf7a971a945dcd3
sha256: ca807ca0a962c0f7e2962a3daafce0c354d81b9b201df4caeecb6de28aaa15aa
sha512: b513cda1eb82458360b6d423d187a6e4bca4b5eac12339dcd118013b4a7534416d659a40731ed3593a541f8c857c4947bc8143c7562aceae9eabcc79b055d7bd
ssdeep: 98304:D1QTXH4s7sv8ZDzz4cK+poPTavbCSiMfpynVPNziLtS0uaAiXLYeUn:pcH4s7sUZfznKz7ICSiMRGVl0tGhaLYp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194261227B299703EC4AA2B354673A11058FFB7ADF416BE1636E4C48CCF265C01E3E665
sha3_384: ff6471dea025649d74a02414c81ea6ea9bd926376107f69c005ed4dc3dde1efe3fe891ab9528b8507d017956773f1e6b
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ktplicity, Inc.
FileDescription: IKViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IKViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Generic.31388216 also known as:

LionicTrojan.Win32.Adload.a!c
MicroWorld-eScanTrojan.Generic.31388216
FireEyeTrojan.Generic.31388216
ALYacTrojan.Generic.31388216
SangforTrojan.Script.Phonzy.C
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.24821a5c
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.DUX.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.Generic.31388216
APEXMalicious
TencentWin32.Trojan-downloader.Adload.Daz
Ad-AwareTrojan.Generic.31388216
EmsisoftTrojan.Generic.31388216 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.moderate.ml.score
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.SZ9036
AviraHEUR/AGEN.1237235
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D1DEF238
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4789003
McAfeeArtemis!053549C950AE
VBA32TrojanDownloader.AdLoad
MalwarebytesAdware.DownloadAssistant
AvastWin32:Trojan-gen
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Generic.31388216?

Trojan.Generic.31388216 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment