Malware

Should I remove “Generic.BrResMon.1.F42F0B4E”?

Malware Removal

The Generic.BrResMon.1.F42F0B4E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.F42F0B4E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Albanian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

www.billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
boatshowradio.com
dna-cp.com
acbt.fr
r3.o.lencr.org
wpakademi.com
www.cakav.hu
www.mimid.cz
6chen.cn
goodapd.website
oceanlinen.com
tommarmores.com.br
nesten.dk
zaeba.co.uk
www.n2plus.co.th
koloritplus.ru
h5s.vn
marketisleri.com
www.toflyaviacao.com.br
www.rment.in
www.lagouttedelixir.com
www.krishnagrp.com
big-game-fishing-croatia.hr
ocsp.digicert.com
mauricionacif.com
www.ismcrossconnect.com
aurumwedding.ru
test.theveeview.com
relectrica.com.mx
bethel.com.ve
vjccons.com.vn
bloghalm.eu
cyclevegas.com
royal.by
www.himmerlandgolf.dk
hoteltravel2018.com
picusglancus.pl
unnatimotors.in
krasnaypolyana123.ru
smbardoli.org
blokefeed.club
evotech.lu
devdev.com.br
graftedinn.us
top-22.ru
simetribilisim.com
edgedl.me.gvt1.com

How to determine Generic.BrResMon.1.F42F0B4E?


File Info:

crc32: 31CF5607
md5: 5b2485469fd80a13b151f7f431d9b944
name: 5B2485469FD80A13B151F7F431D9B944.mlw
sha1: 9f69f8eaba3b921290e12b9cfcb07110ce7a85b6
sha256: 4be2da31e41155c1efdc45d474acd04b369cfbee4ef1eeabef80174cfae35900
sha512: f6182b5fbff93411febc3534074b303ad97275a5570ba6ea814fa366a22225b738c5432148dff859a404fe8ea074a864d6369e3c2ad0850b3f81525544c0ccb2
ssdeep: 3072:uyK64io9mg5X/MgovEut91xMTC28J978rH7wxT9g3gWBNSQlx:ui4ioQgd/MVvvACyuTCr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 10.1.10.11

Generic.BrResMon.1.F42F0B4E also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25911
ClamAVWin.Trojan.Agent-6685563-0
ALYacTrojan.Ransom.GandCrab
MalwarebytesMalware.AI.3340237792
ZillyaTrojan.GenericKD.Win32.165337
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Kryptik.918f4b60
K7GWTrojan ( 0057c3ac1 )
Cybereasonmalicious.69fd80
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKFC
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.BrResMon.1.F42F0B4E
NANO-AntivirusTrojan.Win32.GandCrypt.fhyqmy
ViRobotTrojan.Win32.R.Agent.204288.Q
SUPERAntiSpywareTrojan.Agent/Generic
MicroWorld-eScanDeepScan:Generic.BrResMon.1.F42F0B4E
TencentMalware.Win32.Gencirc.114d4eeb
Ad-AwareDeepScan:Generic.BrResMon.1.F42F0B4E
ComodoTrojWare.Win32.Coins.A@7ub015
BitDefenderThetaAI:Packer.CFBDFC7A1F
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.5b2485469fd80a13
EmsisoftDeepScan:Generic.BrResMon.1.F42F0B4E (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Chapak.pz
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1121568
MicrosoftTrojan:Win32/Azorult!ml
AegisLabTrojan.Win32.GandCrypt.j!c
GDataDeepScan:Generic.BrResMon.1.F42F0B4E
AhnLab-V3Win-Trojan/Gandcrab05.Exp
Acronissuspicious
McAfeeTrojan-FPSA!5B2485469FD8
VBA32TrojanRansom.GandCrypt
PandaTrj/GdSda.A
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GenAsa!j6D8cElYTqE
IkarusTrojan.Crypt
FortinetW32/Kryptik.GKJF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.BrResMon.1.F42F0B4E?

Generic.BrResMon.1.F42F0B4E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment