Malware

Dropped:Generic.Malware.SFMHX.6B1311D8 malicious file

Malware Removal

The Dropped:Generic.Malware.SFMHX.6B1311D8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Malware.SFMHX.6B1311D8 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup

How to determine Dropped:Generic.Malware.SFMHX.6B1311D8?


File Info:

name: 12A5E6010968EB5D73AC.mlw
path: /opt/CAPEv2/storage/binaries/f42640f1a2c42eb51276d7c43cc8c42dd0d7ac141bdb549f525cfe4e0962ba60
crc32: EFD9E2DA
md5: 12a5e6010968eb5d73ac7bfe6152d86e
sha1: e477d3a78a3930447598fb419c3d534634b59920
sha256: f42640f1a2c42eb51276d7c43cc8c42dd0d7ac141bdb549f525cfe4e0962ba60
sha512: 6bdcbd76749100fc9afaab2fb1dc07a567697c7b5cb7262d73097a75db441aacebfd14ee34073b714bca851ecd26f50e9ad0c4516b4c3756fcdf8184999ffbe0
ssdeep: 24576:Ojtai2W/9hSW4mGLJqNw0bRBk/CHdebUKyZURQ1TgjTs:vW1wW4m19dkCHdeQKyZURQ1EjTs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149754A92F54184B5E81301B18D7EDF20265ABE79576816DB72CE762E4AB32C32077E0F
sha3_384: fd2dd76b60d6b009f8dfdf06511b36ca252986719617c8cee8d65ce39104d4a5811bbcc61b1c78125214f0a8ddfd5f87
ep_bytes: e88fe60000e97bfeffff3b0da0ee0701
timestamp: 2015-02-12 18:50:20

Version Info:

0: [No Data]

Dropped:Generic.Malware.SFMHX.6B1311D8 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Malware.SFMHX.6B1311D8
FireEyeGeneric.mg.12a5e6010968eb5d
CAT-QuickHealWorm.Fadok.A5
McAfeeTrojan-FHDX!12A5E6010968
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005645831 )
K7GWTrojan ( 005645831 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34742.NvW@aqNX5Ejk
CyrenW32/FakeDoc.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FakeDoc.K
BaiduWin32.Worm.FakeDoc.a
KasperskyHEUR:Worm.Win32.FakeDoc.gen
BitDefenderDropped:Generic.Malware.SFMHX.6B1311D8
NANO-AntivirusTrojan.Win32.FakeDoc.jpcdzt
AvastWin32:WormX-gen [Wrm]
TencentTrojan.Win32.FakeDoc.ha
Ad-AwareDropped:Generic.Malware.SFMHX.6B1311D8
EmsisoftWorm.FakeDoc (A)
ComodoTrojWare.Win32.Scar.FAKD@5xdxi2
VIPREDropped:Generic.Malware.SFMHX.6B1311D8
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/FakeDoc-B
APEXMalicious
GDataWin32.Trojan.Doc.A
JiangminTrojan.Multi.ksz
AviraHEUR/AGEN.1223860
MAXmalware (ai score=88)
ZoneAlarmHEUR:Worm.Win32.FakeDoc.gen
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FHDX.C5189960
VBA32BScope.Trojan.Agent
ALYacDropped:Generic.Malware.SFMHX.6B1311D8
MalwarebytesMalware.AI.546951358
RisingWorm.Fadok!1.A753 (CLASSIC)
IkarusWorm.Win32.Fakedoc
FortinetW32/FakeDoc.A!worm
AVGWin32:WormX-gen [Wrm]
Cybereasonmalicious.10968e
PandaTrj/Genetic.gen

How to remove Dropped:Generic.Malware.SFMHX.6B1311D8?

Dropped:Generic.Malware.SFMHX.6B1311D8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment