Trojan

Trojan.Generic.31408952 (file analysis)

Malware Removal

The Trojan.Generic.31408952 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31408952 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan.Generic.31408952?


File Info:

name: 8F6B3826874627A980DE.mlw
path: /opt/CAPEv2/storage/binaries/7a69bde5382e2f92a8e9f50f3355ca46b9a7e25f0ba2b4abf74e2395bed0aaaf
crc32: CBEB45B6
md5: 8f6b3826874627a980deed4cf2a3fcf1
sha1: 8767fc1b4017bfe8eb89f8639601620e8623ef7b
sha256: 7a69bde5382e2f92a8e9f50f3355ca46b9a7e25f0ba2b4abf74e2395bed0aaaf
sha512: fdd11bbee83cb342c338533f7921869cbc3ab259b54e86be29860182c013256cfadd9d4c7acc2edba2bd8dd6326e94774ddcbc7b232caf94d4536a19a954f977
ssdeep: 96:Vb+u4l46E3cX4aVfTmBBoJPGPGahiKE7EXjFaRXW7BwppnYYFInk7SHqMxCsETEc:sHO6OI9TZJ+PrnEgXj+SBYIemEIo1Yje
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151A27E346FD61AB6E37BCBB249F292D26579F4327D03D90D80DA47440823B65DDA0E2E
sha3_384: 109804ab95702362ab492b3289cc8c5edbbf4e72c5ccbef1d4c3f1e360924d41b9ede2e41c002ddf15058e36a2306aa3
ep_bytes: 558becb83c200000e893030000535657
timestamp: 2013-09-11 14:39:41

Version Info:

0: [No Data]

Trojan.Generic.31408952 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.31408952
FireEyeGeneric.mg.8f6b3826874627a9
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Generic.31408952
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0050fef41 )
BitDefenderTrojan.Generic.31408952
K7GWTrojan-Downloader ( 00456a071 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Downloader.Waski.k
VirITTrojan.Win32.Generic.BSZC
CyrenW32/Trojan3.AQGI
SymantecDownloader.Upatre!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Trojan.Agent-1279613
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.DownLoad3.cqsjfu
RisingDownloader.Waski!1.A489 (CLASSIC)
Ad-AwareTrojan.Generic.31408952
EmsisoftTrojan.Generic.31408952 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
DrWebTrojan.DownLoader26.64201
ZillyaDownloader.Small.Win32.71821
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Upatre.mz
SophosML/PE-A + Troj/Upatre-XZ
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojanDownloader.Genome.acpr
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.715EEF
MicrosoftTrojanDownloader:Win32/Upatre.A
ArcabitTrojan.Generic.D1DF4338
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataWin32.Trojan.PSE.1DN1M0G
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R83549
Acronissuspicious
McAfeeDownloader-FBWV!8F6B38268746
VBA32Trojan.Downloader
MalwarebytesMalware.AI.3705760751
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan.Win32.Downloader.wf
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Tiny.NIV!tr
BitDefenderThetaGen:NN.ZexaE.34606.bmY@aGKDNwf
AVGWin32:Downloader-WID [Trj]
Cybereasonmalicious.687462
AvastWin32:Downloader-WID [Trj]

How to remove Trojan.Generic.31408952?

Trojan.Generic.31408952 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment