Malware

Should I remove “Generic.BrResMon.1.849D138E”?

Malware Removal

The Generic.BrResMon.1.849D138E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.849D138E virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Indonesian
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

www.bing.com
ramblerads.space

How to determine Generic.BrResMon.1.849D138E?


File Info:

crc32: 4FF10ADB
md5: ef87e32ac692dfcdbd76044a4d52bec2
name: EF87E32AC692DFCDBD76044A4D52BEC2.mlw
sha1: aa9dde591f8e2837e8aaf9df5e56320a129977d1
sha256: 4507c4f6159cc4882cac6c7ec93cc62786142848c67abe3b7ddfadb0948db381
sha512: 9d020f991f49531d1c358a60bbbd649cfccf24367193903041ef0f8b79b0776d49ccc7d1ce36a2bcbdb144fef38e3f3f69964e754073bb5367879c836dd930c8
ssdeep: 3072:jhVPWPNLf/oGlnJq+wBTTCBgStxmpJdXw2OgVtu5SwEnaveP5il7uzXfkommkmY:v+PxIGlnJOBTItxm9VQE/Wu459
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.BrResMon.1.849D138E also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d8371 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Gandcrab.S3838976
ALYacDeepScan:Generic.BrResMon.1.849D138E
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.12412
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Chapak.642fd414
K7GWTrojan ( 0053d8371 )
Cybereasonmalicious.ac692d
CyrenW32/Kryptik.KL.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GLEF
APEXMalicious
AvastFileRepMalware
ClamAVWin.Keylogger.Azorult-9846875-1
KasperskyTrojan.Win32.Chapak.awgn
BitDefenderDeepScan:Generic.BrResMon.1.849D138E
NANO-AntivirusTrojan.Win32.Chapak.fimozb
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanDeepScan:Generic.BrResMon.1.849D138E
Ad-AwareDeepScan:Generic.BrResMon.1.849D138E
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34744.pyW@aKl0e1lG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.ef87e32ac692dfcd
EmsisoftDeepScan:Generic.BrResMon.1.849D138E (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.acba
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.282C29E
MicrosoftTrojan:Win32/Aptdrop.R
AegisLabTrojan.Win32.Chapak.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.BrResMon.1.849D138E
AhnLab-V3Trojan/Win32.Gandcrab.R239399
Acronissuspicious
McAfeeTrojan-FQPW!EF87E32AC692
MAXmalware (ai score=100)
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.3290409913
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Generic@ML.100 (RDML:HE0wncFl961ODaYfu5azkA)
YandexTrojan.GenAsa!/Rx7ZjUahRo
IkarusTrojan-Ransom.Sodinokibi
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.GMSM!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.849D138E?

Generic.BrResMon.1.849D138E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment