Malware

How to remove “Mal/Behav-024”?

Malware Removal

The Mal/Behav-024 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Behav-024 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

t.nxxxn.ga

How to determine Mal/Behav-024?


File Info:

crc32: 3FF88808
md5: 6d241d586baea6d8b32825b1e866866f
name: SQLIOMDSD.exe
sha1: d958f1535f98ce9d07a6af5fa701687005cf5858
sha256: 9d95d4aaf558d5513681f7c0353382deaf25a8ea3b5015dd3c4d3c209868d24c
sha512: fa72a14ce6fbf387539c4695395220e95020e670b6f05974ba9cd843312da1f57c0714f9703fc33042f09916c0398996ddde37e8003aa93ff14117b4ae6053df
ssdeep: 384:V/dxXkROvwuK76kNQexc+v2PVGsa1IJyGxsTKV9K2fId1F7vvxlLYe:V/v0wWzHc+v2Pssa1pGyTdF7Db
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
InternalName: 360DnsOpt
FileVersion: 1.0.0.1058
CompanyName: 360x4e92x8054x7f51x5b89x5168x4e2dx5fc3
ProductName: 360x5b89x5168x536bx58eb
ProductVersion: 1.0.0.1058
FileDescription: 360x5b89x5168x536bx58eb DNSx4f18x9009
OriginalFilename: 360DnsOpt.exe
Translation: 0x0804 0x04b0

Mal/Behav-024 also known as:

DrWebBackDoor.Spy.2436
MicroWorld-eScanGenPack:Generic.Zegost.3.E594680F
FireEyeGeneric.mg.6d241d586baea6d8
CAT-QuickHealTrojan.GenericPMF.S7517963
McAfeeTrojan-INV
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004d57481 )
BitDefenderGenPack:Generic.Zegost.3.E594680F
K7GWTrojan ( 004d57481 )
Cybereasonmalicious.86baea
TrendMicroBKDR_ZEGOST.SM40
BitDefenderThetaAI:Packer.42CBE6FC1F
CyrenW32/Farfli.BA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Zegost-6919579-0
GDataGenPack:Generic.Zegost.3.E594680F
KasperskyHEUR:Trojan.Win32.Generic
RisingBackdoor.Farfli!8.B4 (TFE:5:4kN3d1oYb6H)
Ad-AwareGenPack:Generic.Zegost.3.E594680F
SophosMal/Behav-024
ComodoTrojWare.Win32.PSW.GamePass.F@35ift2
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Agent.atj
ZillyaTrojan.Agent.Win32.1126264
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Mydoom.mc
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
EmsisoftGenPack:Generic.Zegost.3.E594680F (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Farfli.BA.gen!Eldorado
JiangminTrojan/Generic.bcjgw
WebrootW32.Malware.Mlpe
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Zegost
Endgamemalicious (high confidence)
ArcabitGenPack:Generic.Zegost.3.E594680F
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.CD!bit
AhnLab-V3Backdoor/Win32.RL_Zegost.R289802
Acronissuspicious
ALYacGenPack:Generic.Zegost.3.E594680F
TACHYONBackdoor/W32.Farfli.22528.B
VBA32BScope.Trojan.Agent
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ZonerTrojan.Win32.68809
ESET-NOD32Win32/Agent.QJH
TrendMicro-HouseCallBKDR_ZEGOST.SM40
TencentMalware.Win32.Gencirc.10b0c2af
YandexBackdoor.Farfli!S9/WFy1iLOU
IkarusTrojan.Win32.Agent
eGambitUnsafe.AI_Score_56%
FortinetW32/Agent.QJH!tr
AVGWin32:Dropper-ODE [Drp]
AvastWin32:Dropper-ODE [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM18.1.1FD9.Malware.Gen

How to remove Mal/Behav-024?

Mal/Behav-024 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment