Malware

What is “Generic.BrResMon.1.9FA606B5”?

Malware Removal

The Generic.BrResMon.1.9FA606B5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.9FA606B5 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Albanian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
crazermess.top.cp-in-3.webhostbox.net

How to determine Generic.BrResMon.1.9FA606B5?


File Info:

crc32: 29B9DE79
md5: 6ded4ac1b77f79abddbc44f03b40247d
name: 6DED4AC1B77F79ABDDBC44F03B40247D.mlw
sha1: 7b3a0d00e88e7cfb22d42888d8ae724ad8b334f5
sha256: a8db56ec906e01b4099860bf1273e675b311837b38b4fbf6ca68fa83523001ea
sha512: 136dc25e0da11d51bc964f6a18e60af98878c7b90489d2fd7e77b9e534b2aba1e29ae6f78cdefcbef3f52521e584b34eac8631172f6fa0f373a080f625ae49c0
ssdeep: 3072:JlcqayGlHsF5MwRLkad7coFQXccGvo0B7OHxzeaVadBNUoF:JlVMXwWaZZq4voZzeamd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.BrResMon.1.9FA606B5 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23869
CynetMalicious (score: 100)
ALYacDeepScan:Generic.BrResMon.1.9FA606B5
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.164360
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Coins.97ed1903
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.1b77f7
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GKBE
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.Win32.Coins.huf
BitDefenderDeepScan:Generic.BrResMon.1.9FA606B5
NANO-AntivirusTrojan.Win32.Kryptik.fgwvyh
MicroWorld-eScanDeepScan:Generic.BrResMon.1.9FA606B5
TencentWin32.Trojan-qqpass.Qqrob.Wtyb
Ad-AwareDeepScan:Generic.BrResMon.1.9FA606B5
SophosMal/Generic-R + Mal/GandCrab-G
ComodoTrojWare.Win32.PSW.Coins.KA@7tbl0j
BitDefenderThetaGen:NN.ZexaF.34738.nuW@a8y5h8iG
TrendMicroTROJ_FRS.VSN15H18
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.6ded4ac1b77f79ab
EmsisoftDeepScan:Generic.BrResMon.1.9FA606B5 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.auh
AviraHEUR/AGEN.1119073
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27D3392
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.Coins.i!c
ZoneAlarmTrojan-PSW.Win32.Coins.huf
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Win-Trojan/Gandcrab08.Exp
Acronissuspicious
McAfeeTrojan-FPYT!6DED4AC1B77F
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.820234642
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSN15H18
RisingTrojan.Kryptik!1.B5F8 (CLASSIC)
YandexTrojan.GenAsa!BZmnrXP5JXI
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GKJF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.9FA606B5?

Generic.BrResMon.1.9FA606B5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment