Malware

Generic.Malware.SFLlg.30FEE5BA (B) removal

Malware Removal

The Generic.Malware.SFLlg.30FEE5BA (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.SFLlg.30FEE5BA (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • CAPE detected the WarzoneRAT malware family
  • Accesses or creates Warzone RAT directories and/or files

How to determine Generic.Malware.SFLlg.30FEE5BA (B)?


File Info:

name: A6175A3CA4232EE07044.mlw
path: /opt/CAPEv2/storage/binaries/592c109eeebcbae38cedca83ec58834310b722ba36438ddedc82775cf081da2a
crc32: 0DCDA3AC
md5: a6175a3ca4232ee07044b00c21554393
sha1: d53f7c428485b534997d0e7b397abbc6d7d51696
sha256: 592c109eeebcbae38cedca83ec58834310b722ba36438ddedc82775cf081da2a
sha512: c21cfa26f943242b861e96efac4066b86b8adc87858ebcc7bdc1e4214f43aa963b24649fc0ee28ad14988f724bbf0e1441b40315ef6b2a60ad1ae90f61980a7a
ssdeep: 3072:+T9d8ENJxID078Ia0W2t8GhigMCeLg/Qj9LTJ:+pqENJy1Ia0lt8GhiNlg/W9LT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17ED39E13B6AA4035E6B702B02DF93E3A8FEDFE311635C55B53D4948A5C71484EA39393
sha3_384: 254ca8a7e7922563f90d2f9930f50eddd91d6b45122af331f740eab7c7f2213361d582c3bcfa3e3ae37514dd3bfc4f0f
ep_bytes: 558bec83ec4856ff159c8041008365e4
timestamp: 2022-05-28 14:01:07

Version Info:

0: [No Data]

Generic.Malware.SFLlg.30FEE5BA (B) also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Malware.SFLlg.30FEE5BA
FireEyeGeneric.mg.a6175a3ca4232ee0
CAT-QuickHealTrojan.Agentb
ALYacGeneric.Malware.SFLlg.30FEE5BA
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054d10e1 )
K7GWTrojan ( 0054d10e1 )
Cybereasonmalicious.ca4232
CyrenW32/Antiav.INDT-0919
ElasticWindows.Trojan.AveMaria
ESET-NOD32a variant of Win32/Agent.TJS
APEXMalicious
ClamAVWin.Malware.AveMaria-8799014-1
KasperskyTrojan.Win32.Agentb.jiad
BitDefenderGeneric.Malware.SFLlg.30FEE5BA
NANO-AntivirusTrojan.Win32.AntiAV.fljpfv
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10d068b1
Ad-AwareGeneric.Malware.SFLlg.30FEE5BA
SophosML/PE-A + Mal/Behav-039
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.Agent.Win32.2805389
TrendMicroTrojanSpy.Win32.MOCRT.SM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
EmsisoftGeneric.Malware.SFLlg.30FEE5BA (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Backdoor.AveMaria.A
JiangminTrojan.Agentb.mfi
AviraTR/Redcap.ghjpt
ArcabitGeneric.Malware.SFLlg.30FEE5BA
MicrosoftBackdoor:Win32/Remcos!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AveMaria.R263895
Acronissuspicious
McAfeeGenericRXAA-AA!A6175A3CA423
MAXmalware (ai score=80)
VBA32Trojan.Agentb
MalwarebytesBackdoor.AveMaria
TrendMicro-HouseCallTrojanSpy.Win32.MOCRT.SM
RisingStealer.AveMaria!1.BA1C (CLASSIC)
YandexTrojan.GenAsa!++8lN4UW0KE
IkarusTrojan.Win32.AntiAV
MaxSecureTrojan.Malware.7175203.susgen
FortinetW32/Agent.TJS!tr
BitDefenderThetaGen:NN.ZexaF.34742.iyW@au6YxVoi
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Malware.SFLlg.30FEE5BA (B)?

Generic.Malware.SFLlg.30FEE5BA (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment