Spy

Dropped:Generic.Spyagent.5.31312AF7 removal

Malware Removal

The Dropped:Generic.Spyagent.5.31312AF7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Spyagent.5.31312AF7 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (12 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Deletes its original binary from disk
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to disable Windows Defender
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

sokiran.xyz
ipinfo.io
ip-api.com
flamkravmaga.com
www.szwbjs.com
i.spesgrt.com
www.anderesitebrauchen.com
cdn.discordapp.com
a.xyzgame.vip
sslamlssa1.tumblr.com
www.facebook.com
ocsp.digicert.com
crl3.digicert.com
apps.identrust.com
www.listincode.com
g-prtnrs.top
statuse.digitalcertvalidation.com
iplogger.org
shpak125.tumblr.com
crl.identrust.com
iplis.ru
g.symcd.com
ocsp.comodoca.com
crl.comodoca.com
ocsp.usertrust.com
crl.usertrust.com
ocsp.sectigo.com
google.vrthcobj.com

How to determine Dropped:Generic.Spyagent.5.31312AF7?


File Info:

crc32: 0A2A33AB
md5: 70800f0e430d4c9ae411aa87ef26870d
name: 70800F0E430D4C9AE411AA87EF26870D.mlw
sha1: ae3108303791bf71f3d8a22a81950f56d064ec60
sha256: 242b050cc122233e783283296a736b689acfb116c68047c52252a012ba322499
sha512: 1746b4407479ab721c7df75bce318fc0251154732e988bd92a65a686da20f71cd7f9705e5a37bf939f4aa5bc64a722b8a73465c58517dc254377a28d20ac2c4c
ssdeep: 49152:xcBOPkZVi7iKiF8cUvFyPIbUgwvnJTn13QTNyfk5u4ocZ12EwJ84vLRaBtIl9mTO:xsri7ixZUvFyPIbYvnZnpQocu4xZ1FC3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 19.00
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 19.00
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Dropped:Generic.Spyagent.5.31312AF7 also known as:

K7AntiVirusTrojan ( 0057f23b1 )
DrWebTrojan.Inject4.13781
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Agent
ALYacDropped:Generic.Spyagent.5.31312AF7
CylanceUnsafe
K7GWTrojan ( 0057f23b1 )
Cybereasonmalicious.e430d4
CyrenW32/Trojan.VJVU-7820
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Barys-9859531-0
KasperskyTrojan.Win32.CookiesStealer.b
BitDefenderTrojan.GenericKD.37263539
NANO-AntivirusTrojan.Win32.Bsymem.ixqtgf
MicroWorld-eScanTrojan.GenericKD.37263539
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZemsilF.34796.am0@aaGrmQp
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0PGD21
McAfee-GW-EditionRDN/Generic.grp
FireEyeTrojan.GenericKD.37263539
EmsisoftTrojan.Crypt (A)
JiangminTrojan.CookiesStealer.i
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.woetv
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MYK!MTB
ArcabitTrojan.Generic.D2388B07
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataWin32.Trojan.BSE.EZUSKY
McAfeeArtemis!70800F0E430D
MAXmalware (ai score=80)
VBA32Trojan.Inject
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R067C0PGD21
IkarusTrojan.Win32
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
Qihoo-360Win32/Backdoor.SpyAgent.HgIASYsA

How to remove Dropped:Generic.Spyagent.5.31312AF7?

Dropped:Generic.Spyagent.5.31312AF7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment