Malware

Generic.BrResMon.1.1B12FDAB removal tips

Malware Removal

The Generic.BrResMon.1.1B12FDAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.1B12FDAB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed analysis tools by a known file location
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects Sandboxie using a known mutex
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
f4c6y5.top
o4c2m7.top

How to determine Generic.BrResMon.1.1B12FDAB?


File Info:

crc32: A99D9ED3
md5: 7301d836adcb0a52277f9bff28e38de7
name: 7301D836ADCB0A52277F9BFF28E38DE7.mlw
sha1: bfca87f187784594f10b2aa8a9db3e5b77d71a5d
sha256: ca80ddc35c73c1e62611faaaa38f377dd9a61b632eff3ea4db631d729b8ff13c
sha512: faf6e38b771684b19e36a35ec7df71f4cb84647e3c6abaa72a27b0868729bf8262438c488c957f6ce900d61d6da6064268e659238f00994b3ccd61d11fda7227
ssdeep: 3072:iksmLJS//pIq2eDpV0n4iZ3uqufBNZnKyp6fa9iICItkoFfPs2nzAuRPDKl7MQ5:iiLJg72en0jZ6ZykTiIvOoCaPi7MOA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, yuneortiurik
FileVersion: 10.1.10.11
ProductVersion: 10.1.10.11
Translation: 0x0809 0x04b0

Generic.BrResMon.1.1B12FDAB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24561
MicroWorld-eScanDeepScan:Generic.BrResMon.1.1B12FDAB
FireEyeGeneric.mg.7301d836adcb0a52
CAT-QuickHealTrojan.Chapak.ZZ5
Qihoo-360HEUR/QVM20.1.4BAF.Malware.Gen
McAfeeGenericRXEB-KP!7301D836ADCB
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderDeepScan:Generic.BrResMon.1.1B12FDAB
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.6adcb0
TrendMicroRansom_HPGANDCRAB.SMG2
BitDefenderThetaGen:NN.ZexaF.34634.pu0@aeS0r5dO
CyrenW32/S-c5d37cab!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Ransomware.Cryptomix-6489177-0
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
Ad-AwareDeepScan:Generic.BrResMon.1.1B12FDAB
SophosMal/Ransom-FQ
ComodoTrojWare.Win32.NeutrinoPOS.D@7iu3t4
F-SecureHeuristic.HEUR/AGEN.1126869
InvinceaML/PE-A + Mal/Ransom-FQ
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
EmsisoftDeepScan:Generic.BrResMon.1.1B12FDAB (B)
IkarusTrojan-Dropper.Win32.Danabot
JiangminTrojan.Blocker.ifn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1126869
MicrosoftTrojan:Win32/Ursnif.KDS!MTB
ArcabitDeepScan:Generic.BrResMon.1.1B12FDAB
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataDeepScan:Generic.BrResMon.1.1B12FDAB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
ALYacDeepScan:Generic.BrResMon.1.1B12FDAB
MAXmalware (ai score=87)
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GDBZ
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!k6eg88dDJ1Y
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GLKY!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.CRAB.gen

How to remove Generic.BrResMon.1.1B12FDAB?

Generic.BrResMon.1.1B12FDAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment