Malware

How to remove “Dropped:Generic.Malware.SFMHX.20933C75”?

Malware Removal

The Dropped:Generic.Malware.SFMHX.20933C75 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Malware.SFMHX.20933C75 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

wxanalytics.ru

How to determine Dropped:Generic.Malware.SFMHX.20933C75?


File Info:

crc32: 111F1E86
md5: 573b544ea6784bcee4e70723901bfce1
name: urok-41.exe
sha1: fa66ef90703ccaa99545f6d764fa4cbfac1371e8
sha256: b1ea4c169799547fdb869ca40b28d4e6412872271456b4529950bccd82559b68
sha512: 585fc9ba450cc6c311dddbdaedaed31ddcb56f6a9436f9539806e7ae078d7416eae54605d24bbfaba2b166b611f20cae036dc9497986289a120739278c743d4d
ssdeep: 24576:6LILY8Xu/3y8UsG2BgYLicwnkSCHdebUKyZURQ1TgjTI:NYrC8UsGuTwHCHdeQKyZURQ1EjTI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Dropped:Generic.Malware.SFMHX.20933C75 also known as:

BkavW32.IkoztueZ.Trojan
MicroWorld-eScanDropped:Generic.Malware.SFMHX.20933C75
FireEyeGeneric.mg.573b544ea6784bce
CAT-QuickHealWorm.Fadok.A5
McAfeeGenericRXAH-AG!573B544EA678
ZillyaTrojan.Scar.Win32.88546
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderDropped:Generic.Malware.SFMHX.20933C75
K7GWTrojan ( 004c3bbe1 )
K7AntiVirusTrojan ( 004c3bbe1 )
TrendMicroWORM_FAKEDOC_FD050240.UVPM
BaiduWin32.Worm.FakeDoc.a
F-ProtW32/Fakedoc.C
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:WormX-gen [Wrm]
ClamAVWin.Malware.Razy-6723913-0
GDataDropped:Generic.Malware.SFMHX.20933C75
KasperskyTrojan.Win32.Agent.ifdx
NANO-AntivirusTrojan.Win32.Rendoc.faojir
RisingWorm.Fadok!1.A753 (TFE:dGZlOgV/PitkFSzGcA)
Endgamemalicious (high confidence)
EmsisoftWorm.FakeDoc (A)
ComodoTrojWare.Win32.Scar.FAKD@5xdxi2
F-SecureTrojan.TR/ATRAPS.Gen4
DrWebWin32.HLLW.Rendoc.3
VIPRETrojan.Win32.Generic.pak!cobra
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
SophosTroj/FakeDoc-B
IkarusWorm.Win32.Fakedoc
CyrenW32/Fakedoc.PZJA-4253
JiangminWorm.Agent.ju
MaxSecureTrojan.Agent.ifdx
AviraTR/ATRAPS.Gen4
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Scar.jfya
ArcabitGeneric.Malware.SFMHX.20933C75
SUPERAntiSpywareTrojan.Agent/Gen-FakeDoc
ZoneAlarmTrojan.Win32.Agent.ifdx
MicrosoftWorm:Win32/Fadok!rfn
AhnLab-V3Worm/Win32.Fadok.R189010
Acronissuspicious
VBA32Trojan.Agent
ALYacDropped:Generic.Malware.SFMHX.20933C75
Ad-AwareDropped:Generic.Malware.SFMHX.20933C75
MalwarebytesTrojan.FakeDoc
PandaTrj/Genetic.gen
ZonerTrojan.Win32.61633
ESET-NOD32Win32/FakeDoc.A
TrendMicro-HouseCallWORM_FAKEDOC_FD050240.UVPM
TencentMalware.Win32.Gencirc.10b6abd3
YandexTrojan.DownLoader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/FakeDoc.A!worm
BitDefenderThetaGen:NN.ZexaF.34122.LvW@ayVVeyjk
AVGWin32:WormX-gen [Wrm]
Qihoo-360QVM41.1.Malware.Gen

How to remove Dropped:Generic.Malware.SFMHX.20933C75?

Dropped:Generic.Malware.SFMHX.20933C75 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment