Malware

What is “Brresmon.202 (B)”?

Malware Removal

The Brresmon.202 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Brresmon.202 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Brresmon.202 (B)?


File Info:

crc32: 65F0DB56
md5: 4d0128dc0c1d9f66a69a5a4fca7ca979
name: 4D0128DC0C1D9F66A69A5A4FCA7CA979.mlw
sha1: 5f0a3d6f8893f832715be7ffd2b4a114eee2799b
sha256: 30ce961fe5c002f5af7bc63bbbe7a1af42ed261084b3d252ea17906cdf6a98d8
sha512: c4fe5e9051ad519faac486f310d29dbff5e588053a78a52df7a704fa6ce044602444a79234755e257de2089d80bd53fb69ccff0611d2e9c8c76965d6d716f94d
ssdeep: 12288:xn9u4ThuFGKxCiGjUbVxcipOfH/TR3kJtztxXIxQ6:xn9diGKEiG4xxcjH/lkJtzHYxT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 Warmsun Holding
CompanyName: Warmsun Holding
FileDescription: Brominated Librarys
LegalTrademarks: Copyright 2015 Warmsun Holding
Comments: Brominated Librarys
ProductName: Today'sMiroring
ProductVersion: 3.9.9.589
PrivateBuild: 3.9.9.589
OriginalFilename: Today'sMiroring
Translation: 0x0409 0x04b0

Brresmon.202 (B) also known as:

LionicTrojan.Win32.Stealer.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24814
ALYacGen:Variant.Brresmon.202
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.996
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Stealer.554dcf90
K7GWTrojan ( 0056fb651 )
K7AntiVirusTrojan ( 0056fb651 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GLQL
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.ard
BitDefenderGen:Variant.Brresmon.202
NANO-AntivirusTrojan.Win32.Stealer.fjgzrx
MicroWorld-eScanGen:Variant.Brresmon.202
TencentWin32.Trojan-spy.Stealer.Pcsn
Ad-AwareGen:Variant.Brresmon.202
SophosMal/Generic-S
ComodoMalware@#1urnvufu1hzk5
BitDefenderThetaGen:NN.ZexaF.34142.Gq0@aaQiLcji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.hc
FireEyeGeneric.mg.4d0128dc0c1d9f66
EmsisoftGen:Variant.Brresmon.202 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Stealer.fj
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen7
MicrosoftTrojan:Win32/Gandcrab!rfn
ZoneAlarmTrojan-Spy.Win32.Stealer.ard
GDataGen:Variant.Brresmon.202
TACHYONTrojan-Spy/W32.InfoStealer.524288
AhnLab-V3Malware/Win32.Generic.C2764197
Acronissuspicious
McAfeeArtemis!4D0128DC0C1D
VBA32TrojanSpy.Stealer
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
YandexTrojanSpy.Stealer!BLPX3/eAmvE
IkarusTrojan-Spy.Remcos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CNXY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Brresmon.202 (B)?

Brresmon.202 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment