Malware

FileRepMalware [Trj] malicious file

Malware Removal

The FileRepMalware [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FileRepMalware [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Creates a hidden or system file
  • Attempts to execute suspicious powershell command arguments
  • A powershell command using multiple variables was executed possibly indicative of obfuscation

How to determine FileRepMalware [Trj]?


File Info:

name: 7B6B7D04212092626D02.mlw
path: /opt/CAPEv2/storage/binaries/98377bdecddf3ab1cbca6de3121941ad0c9c7bbbb08e9164b34e2ebe824043f2
crc32: A47C5C01
md5: 7b6b7d04212092626d028479998ec87a
sha1: 657ec65183416f2f3a8b4e535139ccb0412d798d
sha256: 98377bdecddf3ab1cbca6de3121941ad0c9c7bbbb08e9164b34e2ebe824043f2
sha512: dfed5a64922abea7b3460c42e76a34f6ec4c3e1905d691bf465faafd17bbe00db81664bf2b898b35d21172a9610f2c118b2b656219e2dae2f21ac29a1098fd6e
ssdeep: 24576:UFq/OuUuBX5RiCcTsfnoyIj66v8n2K7/j3rPRCE:UFq/OuJHipsfoyIm6I2Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149352351EF45CE78C51001BA30E3C694C4158E29F98BB606E7F2F96F9E3DB062A285F5
sha3_384: af7e33dd36772a76211c2529793e28b51cf2168a09e6fb596f2211b2567518a7519307f72c4a57415abb9245bcd1447d
ep_bytes: 60be15f005018dbeeb1f3aff5789e58d
timestamp: 2015-04-18 12:16:08

Version Info:

0: [No Data]

FileRepMalware [Trj] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoader30.28553
MicroWorld-eScanDropped:Trojan.GenericKD.33838997
FireEyeGeneric.mg.7b6b7d0421209262
ALYacDropped:Trojan.GenericKD.33838997
CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
K7AntiVirusTrojan ( 005668261 )
K7GWTrojan ( 005668261 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R007C0RBP22
Paloaltogeneric.ml
ClamAVWin.Malware.Valyria-7564442-0
KasperskyTrojan.VBS.Agent
BitDefenderDropped:Trojan.GenericKD.33838997
NANO-AntivirusTrojan.Script.Agent.dqevbx
SUPERAntiSpywareTrojan.Agent/GenericKD
AvastFileRepMalware [Trj]
TencentVbs.Trojan.Agent.Ajcd
Ad-AwareDropped:Trojan.GenericKD.33838997
EmsisoftDropped:Trojan.GenericKD.33838997 (B)
ComodoMalware@#1z607y93x9sng
TrendMicroTROJ_GEN.R007C0RBP22
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.VB.Valyria
GDataDropped:Trojan.GenericKD.33838997
JiangminTrojan.Multi.dp
WebrootW32.Malware.Gen
ZoneAlarmTrojan.VBS.Agent
MicrosoftHackTool:Win32/Keygen
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3324385
McAfeeArtemis!7B6B7D042120
MAXmalware (ai score=83)
VBA32Trojan.VBS.Agent
MalwarebytesGeneric.Trojan.Malicious.DDS
APEXMalicious
RisingTrojan.Agent!8.B1E (C64:YzY0Oo38pqWyRjLqiqbnUKyij0I)
YandexTrojan.Agent!xH8N+YmFptg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.101288807.susgen
FortinetRiskware/GamePatcher
AVGFileRepMalware [Trj]
Cybereasonmalicious.421209
PandaTrj/CI.A

How to remove FileRepMalware [Trj]?

FileRepMalware [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment