Trojan

Trojan.Generic.31607000 information

Malware Removal

The Trojan.Generic.31607000 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31607000 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan.Generic.31607000?


File Info:

name: 37FB03578AC999A7AFA2.mlw
path: /opt/CAPEv2/storage/binaries/90fce397cb0cc1e7a35806c44057ed047315f0d558572aa47d961df3ed9b5e74
crc32: 7AF8719C
md5: 37fb03578ac999a7afa2a23c6bd303d7
sha1: c94a539cd20141bdb96df512d89ca03ea88822a6
sha256: 90fce397cb0cc1e7a35806c44057ed047315f0d558572aa47d961df3ed9b5e74
sha512: 800e3ffe41db6995b7e956df0c5b655475aaae5bc1c836570cd2de73eacc3263ebd529d6a00b32d5ee04cebcf1ef692c5bf809ff134d9e0f72f5132dadf47bf6
ssdeep: 98304:Ui/TkfFNN+mj3flJtHOqwyBs65r+sjpz24AkhirSBk3r:12h+OTxOqw76r+2pzb6UIr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158163349AD16973EC85B493CFC2CA93E12763EA2373C5158B58E4E0DA0934479AAC1F7
sha3_384: d90c7f045b824b71a77386297bb2edd92d461fe498e7811f76c1a710cf2e7697d5970afc50c59b99832cd0d1fd6048e5
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: GabrielFiles Pro Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Trojan.Generic.31607000 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanTrojan.Generic.31607000
FireEyeTrojan.Generic.31607000
ALYacTrojan.Generic.31607000
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Ekstak.0379ab81
K7GWTrojan ( 005722fe1 )
CyrenW32/Ekstak.CO.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002C0WHA22
Paloaltogeneric.ml
ClamAVWin.Trojan.Filerepmalware-9961435-0
KasperskyTrojan.Win32.Ekstak.amnsg
BitDefenderTrojan.Generic.31607000
CynetMalicious (score: 99)
TencentWin32.Trojan.Ekstak.Lnex
Ad-AwareTrojan.Generic.31607000
SophosMal/Generic-S
VIPRETrojan.Generic.31607000
TrendMicroTROJ_GEN.R002C0WHA22
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Generic.31607000 (B)
GDataTrojan.Generic.31607000
JiangminTrojan.Ekstak.cahl
AviraTR/Drop.Agent.qvlye
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D1E248D8
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Downloader/Win.Generic.C5220580
McAfeeArtemis!37FB03578AC9
MalwarebytesAdware.DownloadAssistant
AvastWin32:TrojanX-gen [Trj]
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan.Generic.31607000?

Trojan.Generic.31607000 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment