Malware

About “Generic.ProcGMar.FD4C31A1” infection

Malware Removal

The Generic.ProcGMar.FD4C31A1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ProcGMar.FD4C31A1 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.ProcGMar.FD4C31A1?


File Info:

name: 494B25BFA48591A1F54F.mlw
path: /opt/CAPEv2/storage/binaries/c7b33996fc9859fc5a23a3af1f287990de6f27cd32f6355ccd406fc614b461f9
crc32: 21344F0B
md5: 494b25bfa48591a1f54fbdc73e2a1ceb
sha1: 67c4bd63a33ef6fb8e1e0a4abca58bf09aed5866
sha256: c7b33996fc9859fc5a23a3af1f287990de6f27cd32f6355ccd406fc614b461f9
sha512: ac597031adc72cf8f57a96edc3b197dff546a864944eadf3cb48b93dd05b562307fda5fab8f034b3a87e3d5bb8fba1a39af92467a8022026ad34ea0c62da7848
ssdeep: 24576:ylnjI9LmIUu6TVaML+TKWmA7xvRVCTAb8/+LqlkvzbZp1dT7pbW4MAQHlh03wBcL:ylY613jTo82LqyvFW48ewBcHIgd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10275E123B3918437D07316789D1F86B5A829BF202F28698A3FE91D4C5F786913D1A3D7
sha3_384: f78de7415cf0b145bce7efbd91ff6a4b765e1a75e8576cbe9f312d238479ca244d762e3452ea85215ccf0bc87259c151
ep_bytes: 558becb9060000006a006a004975f9b8
timestamp: 2010-09-29 06:54:24

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: setup
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Generic.ProcGMar.FD4C31A1 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Click1.62656
MicroWorld-eScanGeneric.ProcGMar.FD4C31A1
ClamAVWin.Trojan.Procgmar-30
FireEyeGeneric.mg.494b25bfa48591a1
SkyhighGeneric BackDoor.adq
McAfeeGeneric BackDoor.adq
MalwarebytesBinder.Trojan.Dropper.DDS
VIPREGeneric.ProcGMar.FD4C31A1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f0b61 )
AlibabaTrojanDropper:Win32/Clustinex.93b7ba9b
K7GWTrojan ( 0040f0b61 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitGeneric.ProcGMar.FD4C31A1
BitDefenderThetaAI:Packer.34D9A29119
VirITTrojan.Win32.Small.LZL
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Binder.NCB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.ProcGMar.FD4C31A1
NANO-AntivirusTrojan.Win32.Click1.bjpsps
AvastWin32:Delf-NZB [Trj]
TencentMalware.Win32.Gencirc.10b50137
EmsisoftGeneric.ProcGMar.FD4C31A1 (B)
F-SecureDropper.DR/Delphi.Gen
ZillyaDropper.Delf.Win32.10819
TrendMicroTROJ_AGENT_014772.TOMB
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Dropper.Gen
AviraDR/Delphi.Gen
MAXmalware (ai score=100)
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.TrojanDropper.Binder.NCBA@4wbzwf
MicrosoftTrojan:Win32/Vindor!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.ProcGMar.FD4C31A1
AhnLab-V3Trojan/Win32.Genome.R39147
VBA32Trojan.Click
ALYacGeneric.ProcGMar.FD4C31A1
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_AGENT_014772.TOMB
RisingDropper.Binder!8.DA (TFE:5:6SyOjx7kEJT)
YandexTrojan.GenAsa!iTfgoccynFM
IkarusTrojan-Dropper.Small
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Delf.NVF!tr
AVGWin32:Delf-NZB [Trj]
DeepInstinctMALICIOUS

How to remove Generic.ProcGMar.FD4C31A1?

Generic.ProcGMar.FD4C31A1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment