Malware

Generik.FBRFFBE information

Malware Removal

The Generik.FBRFFBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.FBRFFBE virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Generik.FBRFFBE?


File Info:

name: DFF903C5483280702CA7.mlw
path: /opt/CAPEv2/storage/binaries/329c56caf01ea3352434142cb0e30020fc3a8bfd5503f9cbfb6b170c361d7092
crc32: 22B1833B
md5: dff903c5483280702ca7e83a39eb5844
sha1: 4b3171cc87d9f467755dd301d7f0c52a75c80142
sha256: 329c56caf01ea3352434142cb0e30020fc3a8bfd5503f9cbfb6b170c361d7092
sha512: cd37c2289116b92d08ef7d7aa3b0085393c5e5de8c51066fe9ab76566676329db90d9d7c6663ca71e0b5a5b80ecbec7db8a3b4c5ca2b6557077b353e2a384787
ssdeep: 6144:1M6fXmfslPcK9e92r7p1yc3jZy+CkLVoQska:1VEsl0K9ewrfZLz5ofR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B22423D7E31A43B5F50608391403EC3C6DA119F32795A76AB64E0538DC12F411AAE7BE
sha3_384: 17b0af299812c6ff38d7fae0abc35b2086c0a1f77ceb264e95dd1a9b07ff89de53bc04184447184bd3f192234377c5e6
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2011-03-25 13:17:42

Version Info:

0: [No Data]

Generik.FBRFFBE also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47490257
FireEyeGeneric.mg.dff903c548328070
McAfeeArtemis!DFF903C54832
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Generic.95621747
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.FBRFFBE
Paloaltogeneric.ml
ClamAVWin.Packed.Mpress-9869657-0
KasperskyTrojan-Ransom.Win32.Agent.bamq
BitDefenderTrojan.GenericKD.47490257
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.47490257
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.GenericKD.47490257 (B)
IkarusWin32.Outbreak
JiangminBackdoor/Androm.cet
WebrootW32.Malware.Gen
AviraTR/Ransom.rlhbm
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2D4A4D1
GDataTrojan.GenericKD.47490257
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47490257
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.RF
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generik.FBRFFBE?

Generik.FBRFFBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment