Malware

How to remove “Dropped:Generic.Malware.S2!prn!.89F39BA9 (B)”?

Malware Removal

The Dropped:Generic.Malware.S2!prn!.89F39BA9 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Malware.S2!prn!.89F39BA9 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

How to determine Dropped:Generic.Malware.S2!prn!.89F39BA9 (B)?


File Info:

name: 3AAE02BEA85010BBFC11.mlw
path: /opt/CAPEv2/storage/binaries/0ae4906f9f927b7d272c30cc1c00762f48a2790881556e210d426ef004713806
crc32: 03CFD181
md5: 3aae02bea85010bbfc11701135b7e169
sha1: 9f39d79554e1e4e8a4744d8e0c4bb37e0f1043e2
sha256: 0ae4906f9f927b7d272c30cc1c00762f48a2790881556e210d426ef004713806
sha512: 947fd248acff5cdb2ed4823cf4009849d9e9c5758bf04079e547581d1453660c13641c31224f6a4c403797cfe2ffd6ea995388562d79ef71d782ba12c916bb04
ssdeep: 12288:6mkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomkgomk6:bVVVVVVVVVVVVVVVp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160957C2131C4C072E29216348976DBB24A2EFC760F7669C73BD8467A5E783D28B35397
sha3_384: 20df47ff75e1fd1f328c274a30b8c2fa5bfa2f49f124868ce1b3748c34dd951b400a0c4e92076cdafb64ae96b751e0ae
ep_bytes: e8a55f0000e989feffffff3500f24100
timestamp: 2021-01-25 08:06:55

Version Info:

CompanyName: Microsoft
FileDescription: Microsoft EXE
FileVersion: 10.19042.746.1
InternalName: MS.exe
LegalCopyright: Copyright (C) 2021
OriginalFilename: Microsoft.exe
ProductName: Microsoft Windows
ProductVersion: 10.19042.746.1
Translation: 0x0809 0x04b0

Dropped:Generic.Malware.S2!prn!.89F39BA9 (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34268
MicroWorld-eScanDropped:Generic.Malware.S2!prn!.89F39BA9
FireEyeGeneric.mg.3aae02bea85010bb
ALYacDropped:Generic.Malware.S2!prn!.89F39BA9
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.tsc (mx-v)
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Generic.Malware.S2!prn!.89F39BA9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ea8501
BitDefenderThetaAI:Packer.AE12D8BE1F
CyrenW32/Agent.DIM.gen!Eldorado
ESET-NOD32a variant of Win32/Agent.OIJ
KasperskyUDS:Worm.Win32.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareDropped:Generic.Malware.S2!prn!.89F39BA9
EmsisoftDropped:Generic.Malware.S2!prn!.89F39BA9 (B)
ZillyaWorm.Generic.Win32.2
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosML/PE-A + Mal/Behav-421
GDataDropped:Generic.Malware.S2!prn!.89F39BA9
JiangminWorm.Generic.aqtf
AviraWORM/Agent.sexgq
Antiy-AVLTrojan/Generic.ASMalwS.34785CA
ArcabitGeneric.Malware.S2!prn!.89F39BA9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Sabsik.R438811
McAfeeGenericRXAA-AA!3AAE02BEA850
MAXmalware (ai score=88)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.FakeMS.Gen
APEXMalicious
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Agent.OIJ!worm
AVGWin32:WormX-gen [Wrm]
AvastWin32:WormX-gen [Wrm]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Dropped:Generic.Malware.S2!prn!.89F39BA9 (B)?

Dropped:Generic.Malware.S2!prn!.89F39BA9 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment