Malware

Generic.Malware.GJSFMBVbg.667C2BD4 removal instruction

Malware Removal

The Generic.Malware.GJSFMBVbg.667C2BD4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.GJSFMBVbg.667C2BD4 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.Malware.GJSFMBVbg.667C2BD4?


File Info:

name: 8E6E5D1D5DAB91F74CFF.mlw
path: /opt/CAPEv2/storage/binaries/3d140cbb68bd1d9c725b36684f2030fc9475043691fe7f8ffb16315727860f97
crc32: D9DBF57F
md5: 8e6e5d1d5dab91f74cffb1eb48551db7
sha1: cef54bbb9cdbd8621cd7ae5490efe8dd1c59d9ae
sha256: 3d140cbb68bd1d9c725b36684f2030fc9475043691fe7f8ffb16315727860f97
sha512: 79bc062878bb9ba7b93985c879a8944baea214c9fd0188b51155934630c7a9c083012fff502016e408e444458ea08f82d2c21fc38506a409ad45d54990571548
ssdeep: 6144:/Rqmpp+amNOGokzLyM9tsLAitQo6tzOKkzIt8gKyfjxfR9D2j4yNy50wlR:ZqmpplpGoGL3etQoMiXM8gxf/Sj4y2lR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB7423AE3B6F4947C29EDCFBC702BB904E2425F3E0BC57E87035DE8D65288B09694516
sha3_384: 084302e35c9f91892d9ddf2bfeb800464beeec8188a82b6d31e4a1942658e9bdadcb6c7d7409610a528ba3dff2c3b064
ep_bytes: 60be00605a008dbe00b0e5ffc7871c70
timestamp: 2004-11-19 12:19:18

Version Info:

0: [No Data]

Generic.Malware.GJSFMBVbg.667C2BD4 also known as:

LionicTrojan.Win32.Prorat.kYMr
Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Malware.GJSFMBVbg.667C2BD4
FireEyeGeneric.mg.8e6e5d1d5dab91f7
CAT-QuickHealBackdoor.Prorat.T8
SkyhighBehavesLike.Win32.Generic.fc
McAfeeBackDoor-AVW
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Prorat.Win32.694
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0020e8c31 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWBackdoor ( 0020e8c31 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Backdoor.Prorat.f
VirITBackdoor.Prorat.B
SymantecTrojan Horse
ESET-NOD32Win32/Prorat
APEXMalicious
TrendMicro-HouseCallBKDR_PRORAT.SMM
ClamAVWin.Trojan.Prorat-37
KasperskyBackdoor.Win32.Prorat.npv
BitDefenderGeneric.Malware.GJSFMBVbg.667C2BD4
NANO-AntivirusTrojan.Win32.Prorat-19.hhti
SUPERAntiSpywareTrojan.Agent/Gen-Prorat
AvastWin32:GenMalicious-BME [Trj]
TencentTrojan.Win32.Prorat.ad
TACHYONBackdoor/W32.Agent.2027052
EmsisoftGeneric.Malware.GJSFMBVbg.667C2BD4 (B)
F-SecureBackdoor.BDS/Prorat.19.M
DrWebTrojan.DownLoad1.39115
VIPREGeneric.Malware.GJSFMBVbg.667C2BD4
TrendMicroBKDR_PRORAT.SMM
SophosTroj/Prorat-19
IkarusBackdoor.Win32.Prorat
JiangminBackdoor/Prorat.ci
GoogleDetected
AviraBDS/Prorat.19.M
VaristW32/ProratP.A
Antiy-AVLTrojan[Backdoor]/Win32.Prorat
KingsoftWin32.Hack.Prorat.npv
MicrosoftBackdoor:Win32/Prorat.L
XcitiumBackdoor.Win32.Agent.AVW85@11x5ri
ArcabitGeneric.Malware.GJSFMBVbg.667C2BD4
ViRobotBackdoor.Win32.Prorat.350764.B
ZoneAlarmBackdoor.Win32.Prorat.npv
GDataWin32.Trojan.PSE1.4OP2OD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Prorat.R1757
VBA32Backdoor.Prorat
ALYacGeneric.Malware.GJSFMBVbg.667C2BD4
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.32410
RisingBackdoor.ProRat.crf (CLASSIC)
YandexTrojan.GenAsa!Br8d4Xxe2vk
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.W32.Prorat.npv
FortinetW32/Prorat.I!tr.bdr
BitDefenderThetaGen:NN.ZexaF.36802.vmHfau9N9aii
AVGWin32:GenMalicious-BME [Trj]
Cybereasonmalicious.d5dab9
DeepInstinctMALICIOUS
alibabacloudBackdoor

How to remove Generic.Malware.GJSFMBVbg.667C2BD4?

Generic.Malware.GJSFMBVbg.667C2BD4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment