Malware

Should I remove “Generic.BrResMon.1.E9474D90”?

Malware Removal

The Generic.BrResMon.1.E9474D90 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.E9474D90 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Generic.BrResMon.1.E9474D90?


File Info:

crc32: B1754C20
md5: 5b849c2b26a7faab9be4f81921219c65
name: 5B849C2B26A7FAAB9BE4F81921219C65.mlw
sha1: f276575109791553bdbd544d0e02edd86bd8b713
sha256: 49c919749517cb5150bf83de96db7a1e34d30b2827f438a21960e0194ad70701
sha512: 541f19548e6632c08cd7dc9751f76986e4efff1f6f8ff7eff673da38570b53ea331422d741693c54966247c9905c6532dbf5784185bc1d08e5948ae5938f4bba
ssdeep: 6144:PG1A8tFeG4zNLhqnHhg0zBBRXE5+NHZR1EZS3fr:+1A8tFGAHK0zfRVLDEZQr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, ignomodoudeb
FileVersion: 10.1.10.11
ProductVersion: 10.1.10.11
Translation: 0x0809 0x04b0

Generic.BrResMon.1.E9474D90 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00526cba1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacDeepScan:Generic.BrResMon.1.E9474D90
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.62
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Ursnif.d18b1a9e
K7GWTrojan ( 00526cba1 )
Cybereasonmalicious.b26a7f
CyrenW32/S-c5d37cab!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCZP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Emotet-6452125-0
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
BitDefenderDeepScan:Generic.BrResMon.1.E9474D90
NANO-AntivirusTrojan.Win32.Yakes.exynrl
ViRobotTrojan.Win32.Ransom.253952.A
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanDeepScan:Generic.BrResMon.1.E9474D90
TencentMalware.Win32.Gencirc.10b6bc41
Ad-AwareDeepScan:Generic.BrResMon.1.E9474D90
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrab.A@7jk3ar
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Virut.dc
FireEyeGeneric.mg.5b849c2b26a7faab
EmsisoftDeepScan:Generic.BrResMon.1.E9474D90 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Diple.bbxy
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_80%
Antiy-AVLTrojan/Generic.ASMalwS.246DEC3
MicrosoftTrojan:Win32/Ursnif.KDS!MTB
ArcabitDeepScan:Generic.BrResMon.1.E9474D90
AegisLabTrojan.Win32.GandCrypt.tphU
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataDeepScan:Generic.BrResMon.1.E9474D90
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeeGenericRXEB-KP!5B849C2B26A7
MAXmalware (ai score=100)
VBA32TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.Bunitu
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
YandexTrojan.GandCrypt!rB7PfXp2qRk
IkarusTrojan.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GLKY!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.E9474D90?

Generic.BrResMon.1.E9474D90 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment