Trojan

Trojan.Generic.31401099 removal tips

Malware Removal

The Trojan.Generic.31401099 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31401099 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Generic.31401099?


File Info:

name: 0B922C0F166ED000AFBD.mlw
path: /opt/CAPEv2/storage/binaries/dff0725f1b32c70a57499803901f92ee2f30b4e0663921b51dbbd5f656b3c32f
crc32: 8FC74422
md5: 0b922c0f166ed000afbde274590beee0
sha1: 4fcc8816cded41d77d86d1c787878e81fb9ddd8f
sha256: dff0725f1b32c70a57499803901f92ee2f30b4e0663921b51dbbd5f656b3c32f
sha512: 48b8f2b04791fb82fc55caa1215cfe9b1be8187637a66a52061c38374f5ecd3548978a99eb1d2088676a1b4625366e912962bfd5b162ae9098e5dc8929bed674
ssdeep: 12288:rco398Nb9ZsbxCIRnwuRtVH7jUkcaqkOzWKiKx1DLSpq:rcm7jw+tVHvTMzWKbnDgq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1957512529B184858FB6C1B359802F6E540A59D3EA4D5F82FF03CBD3E69321876A7324F
sha3_384: dd5d511a25469c54978ed90c398e662493a4d586f9abe2463834ba6c3f91c125c6f6999b92bebd8c06207b54acebc1f2
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2012-11-06 10:57:03

Version Info:

CompanyName: Samsung Urban
FileDescription: Ultead Video
FileVersion: 1, 0, 0, 85
InternalName: Jghdfsfd Porker
LegalCopyright: Copyright (C) 2012
OriginalFilename: Maggo Play
ProductName: Gtsfwe
ProductVersion: 1, 0, 0, 85
Translation: 0x0412 0x04b0

Trojan.Generic.31401099 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31401099
FireEyeGeneric.mg.0b922c0f166ed000
CAT-QuickHealTrojan.Gupboot.B.mue
ALYacGenPack:Generic.Urelas.55C0ED56
CylanceUnsafe
VIPRETrojan.Win32.Urelas.b (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Generic.31401099
K7GWTrojan ( 004da1581 )
K7AntiVirusTrojan ( 004da1581 )
BaiduWin32.Rootkit.Agent.s
VirITBackdoor.Win32.Generic.BVHO
CyrenW32/Xpack.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.AR
APEXMalicious
ClamAVWin.Trojan.Agent-1139021
KasperskyRootkit.Win32.Plite.pvd
NANO-AntivirusTrojan.Win32.AVKill.cmtium
RisingTrojan.Agent!1.9D23 (CLASSIC)
EmsisoftTrojan.Generic.31401099 (B)
ComodoTrojWare.Win32.GupBoot.BFC@5szi8p
DrWebTrojan.AVKill.24829
ZillyaTrojan.Urelas.Win32.90
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tt
SophosML/PE-A + Troj/Backdr-IJ
SentinelOneStatic AI – Malicious PE
JiangminRootkit.Plite.o
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.2B8365
KingsoftHeur.SSC.2777335.1216.(kcloud)
MicrosoftTrojan:Win32/Gupboot.B
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataWin32.Trojan.PSE.1EENH8U
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wecod.R41369
McAfeeGeneric BackDoor.aeu
VBA32Rootkit.Plite
MalwarebytesMalware.AI.2087708938
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b07955
YandexTrojan.GenAsa!fWGIDzv5BFM
IkarusTrojan.BAT.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Plite.RTK!tr
BitDefenderThetaGen:NN.ZexaF.34182.Hnxaa4mLh8oO
AVGWin32:Malware-gen
Cybereasonmalicious.f166ed
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Generic.31401099?

Trojan.Generic.31401099 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment