Malware

What is “Generic.Malware.SFPHYBdPk!g.25F1BEA1”?

Malware Removal

The Generic.Malware.SFPHYBdPk!g.25F1BEA1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.SFPHYBdPk!g.25F1BEA1 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify a Browser Helper Object
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Generic.Malware.SFPHYBdPk!g.25F1BEA1?


File Info:

name: E7EEC1F2617A551554ED.mlw
path: /opt/CAPEv2/storage/binaries/5776e372ea84f788a71ea8959bff202b4ea644768a9b712faf0a7f10b72acccb
crc32: 272E183D
md5: e7eec1f2617a551554edd3ce921c741d
sha1: 390ea2ea2e7e835f0e28565f65462790a1592000
sha256: 5776e372ea84f788a71ea8959bff202b4ea644768a9b712faf0a7f10b72acccb
sha512: fc217f223e6441cc285b7b5be8a4136e96d5d2b8fb666779f25b91ce6554bc5af4adf87364a005c43a71f35e34e33d7a1b0ce4ecc6ea673df2e6e4d6285fb96d
ssdeep: 3072:+1nLxSXCEafZ/p59eaJYLFpZ5dsCYMUzjGcl:+xSyPhgauZMvHG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126B512C92DD43E83F74607B97B33B1F689ED796518E4364B78C1849A60350BAF190AA3
sha3_384: 3c3c34850e4ef78928b45c88573665e0987cb583b08cd3c035c0331006e420f961333981a1d9ca9ecad194df8a52f26a
ep_bytes: 558bec81ec00080000dbe29b0f01e0a8
timestamp: 2001-09-25 00:56:06

Version Info:

CompanyName: Intel NGO
FileDescription: Intel Motherboard Service
FileVersion: 6, 5, 1, 1
InternalName: Intel NGO
LegalCopyright: Copyright (C) 2007
LegalTrademarks: Intel Corp.
OriginalFilename: NGO
ProductName: NGO
ProductVersion: 6, 5, 0, 0
Translation: 0x0409 0x04b0

Generic.Malware.SFPHYBdPk!g.25F1BEA1 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
ALYacDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
BitDefenderDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.2617a5
SymantecBackdoor.Tinybaron
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.RLQ
APEXMalicious
KasperskyBackdoor.Win32.MiniDuke.be
NANO-AntivirusTrojan.Win32.PEF.ctgafr
RisingDownloader.Agent!8.B23 (RDMK:cmRtazpowhZtvCKZnx7cqevdMMQ5)
Ad-AwareDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
EmsisoftDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Click2.32979
ZillyaTrojan.Agent.Win32.574196
FireEyeGeneric.mg.e7eec1f2617a5515
SophosML/PE-A + Mal/EncPk-QW
IkarusTrojan.Win32.Patched
GDataDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
JiangminTrojan/Generic.eky
AviraTR/Dropper.Gen
ArcabitDeepScan:Generic.Malware.SFPHYBdPk!g.25F1BEA1
ZoneAlarmHEUR:Worm.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.C32343
MAXmalware (ai score=89)
VBA32BScope.Trojan-Dropper.2573
PandaTrj/Genetic.gen
TencentTrojan.Win32.Cosmu.b
SentinelOneStatic AI – Malicious PE
FortinetW32/Cosmu.SDR!tr
BitDefenderThetaAI:Packer.B81C72981F
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Generic.Malware.SFPHYBdPk!g.25F1BEA1?

Generic.Malware.SFPHYBdPk!g.25F1BEA1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment