Malware

What is “Brresmon.196”?

Malware Removal

The Brresmon.196 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Brresmon.196 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings

How to determine Brresmon.196?


File Info:

crc32: E5FADF9E
md5: a391937aeb3b8da21538f780981cecad
name: A391937AEB3B8DA21538F780981CECAD.mlw
sha1: a7056fd24a410b4ec78f33bed598a01e8a5fa5a2
sha256: f19dc131f5bc945766d82e0bcd49956f4119a9ab04fb2479cea449c53058833a
sha512: 42e6da37b8283361c8847cafaaaf061e437e28bedf8b281ed46b0474ea849988bfa8d4ca356130b20677c63fca9c44215cf50131afcaad5a29869e026b22ebb1
ssdeep: 6144:U/0OHAX+MWkp88fEwCh4UTnE2LZpMSaiS/kcBpy:40w6+MhNU7dLZ2iS/k0y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9AMS Software.
InternalName: Reconsidering
FileVersion: 2.8.8.5
CompanyName: AMS Software
LegalTrademarks: Copyright xa9AMS Software.
Comments: Many Marketers Vbscript Qemu 1998
ProductName: Reconsidering
ProductVersion: 2.8.8.5
FileDescription: Many Marketers Vbscript Qemu 1998
OriginalFilename: Reconsidering.exe
Translation: 0x0409 0x04b0

Brresmon.196 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Brresmon.196
FireEyeGeneric.mg.a391937aeb3b8da2
ALYacGen:Variant.Brresmon.196
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Brresmon.196
Cybereasonmalicious.aeb3b8
SymantecTrojan Horse
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kltz
NANO-AntivirusTrojan.Win32.Blocker.evfupm
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Brresmon.196
EmsisoftGen:Variant.Brresmon.196 (B)
ComodoMalware@#2b8dvnxvpts9j
F-SecureHeuristic.HEUR/AGEN.1127217
DrWebWin32.HLLM.Reset.493
TrendMicroMal_MiliCry-1h
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
SophosMal/Generic-S
IkarusVirus.Win32.Ramnit
AviraHEUR/AGEN.1127217
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=99)
MicrosoftVirTool:Win32/Injector
ArcabitTrojan.Brresmon.196
ZoneAlarmTrojan-Ransom.Win32.Blocker.kltz
GDataGen:Variant.Brresmon.196
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!A391937AEB3B
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FQRN
TrendMicro-HouseCallMal_MiliCry-1h
TencentWin32.Trojan.Blocker.Lmaj
YandexTrojan.Blocker!9ZSI5Pml0Hk
FortinetW32/Kryptik.FRDY!tr
BitDefenderThetaGen:NN.ZexaF.34590.rq0@aabXmMpi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.84b

How to remove Brresmon.196?

Brresmon.196 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment