Malware

Dropped:Generic.Malware.F!dld!.0BFC8AF7 malicious file

Malware Removal

The Dropped:Generic.Malware.F!dld!.0BFC8AF7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Malware.F!dld!.0BFC8AF7 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropped:Generic.Malware.F!dld!.0BFC8AF7?


File Info:

name: 250724711214D8BCF481.mlw
path: /opt/CAPEv2/storage/binaries/2d8592efb48320f82543336e5ebb8c59b8d0daf77138ba953bddcc2202f1f37d
crc32: B6EFDD92
md5: 250724711214d8bcf481cdce957ae2c1
sha1: faedce54bfa675852c123dced9fe4d52aa0b8d2c
sha256: 2d8592efb48320f82543336e5ebb8c59b8d0daf77138ba953bddcc2202f1f37d
sha512: f9c7e78ae854fe3b5c611d04f2ee6d29058e817ab920304054515a56c26889962ab2265169f83c0ecf310f98dd56b403b7ce30a566314f00ed1a39620967c15e
ssdeep: 768:lvQ5qDLHRdw2iPSMEk/6KEqEMb96dyXJ80EEEEEMeXXXG:lvQoLHjw2iWPKEq7OyX60MXXXG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC233B8B5B511591D3B3473C109233AA4CFB3C75490FA225EE81B99B1CF8D1AAA3DD47
sha3_384: 90d27f3d69baf875d87edffe1cdc60facd63b0f315aa303ae7298a1f6a0e38b8e34f6c6201f24e34a0b97d9f6e947382
ep_bytes: 558bec6aff6870614000684039400064
timestamp: 2016-01-15 16:42:28

Version Info:

Comments:
CompanyName: Yagu Music
FileDescription: Clien RunProcess Local
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Yagu Music
PrivateBuild:
ProductName: Yagu Music® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Tra: 0x0000 0x0000

Dropped:Generic.Malware.F!dld!.0BFC8AF7 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanDropped:Generic.Malware.F!dld!.0BFC8AF7
McAfeeGenericRXHB-SG!250724711214
Cylanceunsafe
ZillyaTrojan.ServStart.Win32.23448
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
K7GWTrojan ( 0054d1101 )
Cybereasonmalicious.11214d
BitDefenderThetaGen:NN.ZexaF.36196.cu1@aqhcxscj
CyrenW32/S-677c9ef6!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/ServStart.RC
APEXMalicious
ClamAVWin.Trojan.Nitol-6335025-0
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderDropped:Generic.Malware.F!dld!.0BFC8AF7
NANO-AntivirusTrojan.Win32.GenKryptik.fnpygk
AvastWin32:Nitol-B [Trj]
TencentTrojan.Win32.Nitol.wa
EmsisoftDropped:Generic.Malware.F!dld!.0BFC8AF7 (B)
F-SecureTrojan.TR/AD.Nitol.ienxr
DrWebTrojan.DownLoader24.51669
VIPREDropped:Generic.Malware.F!dld!.0BFC8AF7
TrendMicroDDOS_NITOL.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.pt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.250724711214d8bc
SophosTroj/Agent-BEMJ
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.ServStart.F
JiangminTrojanDDoS.Nitol.cm
AviraTR/AD.Nitol.ienxr
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitGeneric.Malware.F!dld!.0BFC8AF7
ViRobotDropper.Agent.54110
ZoneAlarmHEUR:Trojan.Win32.Staser.gen
MicrosoftDDoS:Win32/Nitol.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Nitol.R573593
VBA32BScope.Trojan.Downloader
ALYacDropped:Generic.Malware.F!dld!.0BFC8AF7
MAXmalware (ai score=80)
MalwarebytesGeneric.Trojan.ServStart.DDS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.82643
TrendMicro-HouseCallDDOS_NITOL.SMC
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
YandexTrojan.ServStart!ySaEE1rIKOk
SentinelOneStatic AI – Suspicious PE
MaxSecureDDoS.W32.Nitol.gen
FortinetMalwThreat!E1E6IV
AVGWin32:Nitol-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Dropped:Generic.Malware.F!dld!.0BFC8AF7?

Dropped:Generic.Malware.F!dld!.0BFC8AF7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment