Trojan

Trojan.Generic.31749379 removal

Malware Removal

The Trojan.Generic.31749379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.31749379 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Generic.31749379?


File Info:

name: 3F7EBC16CF4F539ABF82.mlw
path: /opt/CAPEv2/storage/binaries/6940808a0317e7f8972936d78c92abdf36ba008b917e0cbf863af9d1a788cc59
crc32: 561D8DAB
md5: 3f7ebc16cf4f539abf8294e39bea5c3a
sha1: eee873a3d5fd74e5e302d9320ace20b9c0eaa332
sha256: 6940808a0317e7f8972936d78c92abdf36ba008b917e0cbf863af9d1a788cc59
sha512: b5473856b5a8dd049c633bdd5cb6ebab377cc36cd75ba4e48f839d153170e554e688164fe85335d60ef1eec0ab57ea856a454c4274340ca170b55f67ff17a3a1
ssdeep: 98304:o8tXhpDZY3BnOZxzorDal/dWG+fz0ZKOPRjdhs9:oCZxZJorYAQYOPVs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15516D022E552C0B2E115167082B757386F30AFB25D308A97B794FDF52E723B2676324E
sha3_384: b375a0f05eb735b9955af88190c17c6bafed1d15c7be4bb15ee134014085379ea30733fc081684d2cf0c74b512ec09ba
ep_bytes: 558bec6aff68a02f7d006864ac510064
timestamp: 2022-09-09 08:51:52

Version Info:

FileVersion: 2.1.0.0
FileDescription: 代练妈妈抢单器
ProductName: 趣代练抢单器
ProductVersion: 2.1.0.0
CompanyName: 仟亿电竞
LegalCopyright: 仟亿电竞 版权所有
Comments: 本程序使用易语言编写(http://www.dywt.com.cn)
Translation: 0x0804 0x04b0

Trojan.Generic.31749379 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lIa2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.31749379
FireEyeGeneric.mg.3f7ebc16cf4f539a
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.Generic.31749379
K7GWTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34682.@t0@aeJp!0pb
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Malware.Agen-7172367-0
APEXMalicious
Ad-AwareTrojan.Generic.31749379
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
JiangminTrojan.Generic.yyqv
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1TYMTF4
GoogleDetected
MAXmalware (ai score=88)
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.65CA!tr
AVGWin32:GenMalicious-BRA [Trj]
Cybereasonmalicious.3d5fd7
AvastWin32:GenMalicious-BRA [Trj]

How to remove Trojan.Generic.31749379?

Trojan.Generic.31749379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment