Malware

Should I remove “Generic.BrResMon.1.70D7A5FF”?

Malware Removal

The Generic.BrResMon.1.70D7A5FF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.70D7A5FF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Indonesian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a registry key or value with NUL characters to avoid detection with regedit
  • Installs itself for autorun at Windows startup
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to disable browser security warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.BrResMon.1.70D7A5FF?


File Info:

crc32: 314F2CDE
md5: 4eea4bc227ead0c1248086ca70181451
name: 4EEA4BC227EAD0C1248086CA70181451.mlw
sha1: 6d324f8d38e5264a6b62272063a8bb9a48fb17df
sha256: 1163de499ef51dcbe9aa6105a7210b8d55b93d8c5ca039687199e8c109fd8845
sha512: 5f1b0fac84c4df410f3b3f1ef41f9a6a96247fd94ccb4b8c21291048ed042a8268c41c71c1ddbcad687924ceb11fae43f2d6c2a9821e30627b80865218e1b107
ssdeep: 3072:ADZ0eM0ZhXZy77/7j7VIIi5+PS/OsVJpORcdlpatNrMaVAu5A3mIRLRPo7Ulhxi:+lM07w7DXpIIiYS/cRcbIUmwFowowWZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.BrResMon.1.70D7A5FF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d9d41 )
Elasticmalicious (high confidence)
DrWebTrojan.TinyNuke.9
CynetMalicious (score: 100)
CAT-QuickHealRansom.Gandcrab.S3838976
ALYacDeepScan:Generic.BrResMon.1.70D7A5FF
CylanceUnsafe
ZillyaTrojan.Fareit.Win32.28169
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:Win32/Fareit.8841a529
K7GWTrojan ( 0053d9d41 )
Cybereasonmalicious.227ead
CyrenW32/Kryptik.KL.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GLEM
APEXMalicious
AvastFileRepMalware
ClamAVWin.Keylogger.Azorult-9846875-1
KasperskyTrojan-PSW.Win32.Fareit.ekuj
BitDefenderDeepScan:Generic.BrResMon.1.70D7A5FF
NANO-AntivirusTrojan.Win32.Fareit.fimpux
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanDeepScan:Generic.BrResMon.1.70D7A5FF
TencentWin32.Trojan-qqpass.Qqrob.Piko
Ad-AwareDeepScan:Generic.BrResMon.1.70D7A5FF
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34770.pyW@aWv5wmnG
TrendMicroTSPY_FAREIT.THAOOIAH
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.4eea4bc227ead0c1
EmsisoftDeepScan:Generic.BrResMon.1.70D7A5FF (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.vw
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Aptdrop.R
AegisLabTrojan.Win32.Fareit.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.BrResMon.1.70D7A5FF
AhnLab-V3Trojan/Win32.Gandcrab.R239399
Acronissuspicious
McAfeeTrojan-FQPW!4EEA4BC227EA
MAXmalware (ai score=100)
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.3290409913
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_FAREIT.THAOOIAH
RisingTrojan.Generic@ML.97 (RDML:OpyerJyX7O9Rzuw9K+w7xw)
YandexTrojan.GenAsa!XbedfZ9U7xQ
IkarusTrojan-Ransom.Sodinokibi
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GMSM!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.70D7A5FF?

Generic.BrResMon.1.70D7A5FF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment