Trojan

Trojan.GenericRI.S31670896 malicious file

Malware Removal

The Trojan.GenericRI.S31670896 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GenericRI.S31670896 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format

How to determine Trojan.GenericRI.S31670896?


File Info:

name: 7E3A76F0B2A1F7DE75F9.mlw
path: /opt/CAPEv2/storage/binaries/2772c0cc133bf4cde71507e4b2736c6f9602c9109176b30d7c25bc22f72e632f
crc32: 51D6B5D2
md5: 7e3a76f0b2a1f7de75f96e80487bae0d
sha1: 4a0764179bfd00307050db2a45de58b01dc7487e
sha256: 2772c0cc133bf4cde71507e4b2736c6f9602c9109176b30d7c25bc22f72e632f
sha512: a30d1dfeebd0a43e1e2400e43b2771b6cbfbdb6b51d092d48e845c9c25fef8d3c6f2236320c773ca5ffa93fe3ae7298efb36308c6dde7d9be31dc2b94497677d
ssdeep: 24576:haUT5Cc5GEwIt0hy4sfZLZmN1VUZmgk3uql6lrdU7Qw1C30mOTb0svZd8HtiwC/s:haUdT5LntT31ZmXiZmgk3uql6lrdU7Qt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B145C017F68003B1C5D212722D6E45F25B3BAD7A52E9DA9120D8F10D3633E24937BAED
sha3_384: df0c23932a05298a4be082ebf9dc1763be7094225e803cd2596b6af58582e9b19a4df1916629c5fc06f3b16e6068c8a3
ep_bytes: e8ff190000e97ffeffff3b0da0404100
timestamp: 2007-04-07 04:20:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Word
FileVersion: 14.0.6024.1000
InternalName: WinWord
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.6024.1000
Translation: 0x0000 0x04e4

Trojan.GenericRI.S31670896 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Facido.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.98267
FireEyeGeneric.mg.7e3a76f0b2a1f7de
CAT-QuickHealTrojan.GenericRI.S31670896
SkyhighBehavesLike.Win32.Generic.tc
ALYacTrojan.GenericKDZ.98267
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3901643
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:Win32/Facido.8132db52
K7GWTrojan ( 005490181 )
K7AntiVirusTrojan ( 005490181 )
BitDefenderThetaAI:Packer.089F9E7C1F
VirITTrojan.Win32.Salgorea.B
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RTY
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DD124
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Facido-9768987-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.98267
NANO-AntivirusTrojan.Win32.Fakealert.fhnukn
TencentTrojan.Win32.Agent.hct
EmsisoftTrojan.GenericKDZ.98267 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Fakealert.58572
VIPRETrojan.GenericKDZ.98267
TrendMicroTROJ_GEN.R002C0DD124
Trapminemalicious.high.ml.score
SophosTroj/Mdrop-JTO
IkarusTrojan.Win32.Dropper
GDataWin32.Trojan.PSE.1X3M469
JiangminTrojan.Generic.hrsto
WebrootW32.Trojan.Gen
VaristW32/Agent.ION.gen!Eldorado
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[Dropper]/Win32.Facido
KingsoftWin32.HeurC.KVMH008.a
XcitiumTrojWare.Win32.TrojanDropper.Facido.A@7d50kc
ArcabitTrojan.Generic.D17FDB
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Facido.A!bit
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.FC.C5393477
Acronissuspicious
McAfeeGenericRXMT-FC!7E3A76F0B2A1
GoogleDetected
VBA32BScope.TrojanDropper.Agent
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingDropper.Agent!1.B38C (CLASSIC)
YandexTrojan.Agent!y5PHKjCEtCQ
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.RTY!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Facido.A!bit

How to remove Trojan.GenericRI.S31670896?

Trojan.GenericRI.S31670896 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment