Malware

Generic.Malware.GJSFMBVbg.8348783F malicious file

Malware Removal

The Generic.Malware.GJSFMBVbg.8348783F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.GJSFMBVbg.8348783F virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:5110, 0.0.0.0:5112, 0.0.0.0:51100
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Generic.Malware.GJSFMBVbg.8348783F?


File Info:

name: DD74800E419724789416.mlw
path: /opt/CAPEv2/storage/binaries/1cc88123f5a385d49052ba369aa21324c6dbfbca75a3deef72c6445e30439959
crc32: E2BBDEC7
md5: dd74800e419724789416c58b9d9dfbb1
sha1: fe7cc3540ae848e098ca7b8cc5b1043df2eba630
sha256: 1cc88123f5a385d49052ba369aa21324c6dbfbca75a3deef72c6445e30439959
sha512: f6e474ddd6dca52a3ddee7f555b15bc4d314a8765fe9b8bb832b0a1cf3061839ed9a71c74cd224ff2e25cab06d9d4f96e3b43edb25af61500137aa9534640279
ssdeep: 6144:lF8jQMQtt0JiWBFSbEbu+jaTvacPbkgo54UCodblRGxc1xDtFWA9rmNlbrnWy7og:lF8jAtYB22azaLgzaLUcDDWCrmzWx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B57423D2538D4BEDC4F4117A6C83F635AE26238EA6B71CE3D36D85623352E963362C41
sha3_384: 5227e4a87e258d0d1389e97bb6ecb12c8b2a8e8f7f2c91063aafdd1483e80f67df7adf4766b44282acd62ea30efe0bad
ep_bytes: 60be00905a008dbe0080e5ffc7879c90
timestamp: 2005-06-02 10:36:26

Version Info:

0: [No Data]

Generic.Malware.GJSFMBVbg.8348783F also known as:

Elasticmalicious (high confidence)
DrWebWin32.HLLW.MyBot
MicroWorld-eScanGeneric.Malware.GJSFMBVbg.8348783F
FireEyeGeneric.mg.dd74800e41972478
CAT-QuickHealBackdoor.Prorat.AH8
McAfeeBackDoor-AVW
CylanceUnsafe
ZillyaBackdoor.Prorat.Win32.9636
SangforVirus.Win32.Save.a
K7AntiVirusBackdoor ( 000237271 )
K7GWBackdoor ( 000237271 )
Cybereasonmalicious.e41972
BitDefenderThetaGen:NN.ZexaF.34212.vmGfaShzm2ki
VirITBackdoor.Prorat.GEN
CyrenW32/Hupigon.D.gen!Eldorado
SymantecW32.IRCBot.Gen
ESET-NOD32Win32/Prorat.NAH
TrendMicro-HouseCallBKDR_PRORAT.BL
Paloaltogeneric.ml
ClamAVWin.Trojan.Prorat-31
KasperskyBackdoor.Win32.Prorat.mj
BitDefenderGeneric.Malware.GJSFMBVbg.8348783F
NANO-AntivirusTrojan.Win32.Prorat.brahkz
SUPERAntiSpywareBackdoor.Prorat/Variant
AvastWin32:Noesis-C [Trj]
TencentMalware.Win32.Gencirc.10b3dc6e
Ad-AwareGeneric.Malware.GJSFMBVbg.8348783F
SophosTroj/Prorat-Fam
ComodoBackdoor.Win32.Agent.AVW46@11x5pw
BaiduWin32.Backdoor.Prorat.h
VIPREBackdoor.Win32.Prorat.aa (v)
TrendMicroBKDR_PRORAT.BL
McAfee-GW-EditionBehavesLike.Win32.Pluto.fc
EmsisoftGeneric.Malware.GJSFMBVbg.8348783F (B)
IkarusPacker.Win32.Klone
GDataGeneric.Malware.GJSFMBVbg.8348783F
JiangminBackdoor/Agent.mln
AviraBDS/Backdoor.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.657B
KingsoftHeur.SSC.2687307.1216.(kcloud)
ViRobotBackdoor.Win32.Prorat.347180.B
ZoneAlarmBackdoor.Win32.Prorat.ft
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Prorat.R1757
Acronissuspicious
ALYacGeneric.Malware.GJSFMBVbg.8348783F
TACHYONBackdoor/W32.Prorat.2035200
VBA32Backdoor.Prorat
MalwarebytesTrojan.Injector
APEXMalicious
RisingBackdoor.Prorat!1.A068 (RDMK:cmRtazqwiSe1lsNpEEuKhH36yD/Z)
YandexTrojan.GenAsa!CAbGAOo599w
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Prorat.AE!tr.bdr
AVGWin32:Noesis-C [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Generic.Malware.GJSFMBVbg.8348783F?

Generic.Malware.GJSFMBVbg.8348783F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment