Malware

Mal/Behav-398 removal instruction

Malware Removal

The Mal/Behav-398 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Behav-398 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

update.kuai-go.com
usa.kuai-go.com
korea.kuai-go.com
fwq.kuai-go.com

How to determine Mal/Behav-398?


File Info:

crc32: F3A0864D
md5: 339bec2b3e598b98218c16ed1e762b2a
name: m.exe
sha1: 001a4bb41655c17eca6921420af00bb36fdc0922
sha256: 51b3d6b1add70e3b14c8ea224dd804467523a4fe2360021576f559761331a084
sha512: f0e53e38169e68856d3cd326c12e7f6174b169f6780fb1c5c81db94cf3c0b3bb47654415099f83ee8ccee119e6609306e1867777c8688857bae4346f181e1e25
ssdeep: 3072:GcD/8FOh8v1VWznIFfqdETVP19F5tEB3N8Ns0Fb8xESsfxjoV:GKlSdVsnAfS61jEdWNFCtsJC
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Microsoft Windows Operating System
InternalName: Microsoft Windows Operating System
FileVersion: 2.1.0.0
CompanyName: Microsoft Windows Operating System
LegalTrademarks: Microsoft Windows Operating System
Comments: Microsoft Windows Operating System
ProductName: Microsoft
ProductVersion: 1.0.0.0
FileDescription: Microsoft Windows Operating System
OriginalFilename: Microsoft
Translation: 0x0809 0x04e4

Mal/Behav-398 also known as:

MicroWorld-eScanTrojan.GenericKD.41267737
CAT-QuickHealTrojan.Generic
McAfeeRDN/Generic.hbg
MalwarebytesTrojan.Injector
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005376ae1 )
BitDefenderTrojan.GenericKD.41267737
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.b3e598
TrendMicroTrojan.Win32.ZEGOST.B
BitDefenderThetaAI:Packer.37A5E3DF1C
CyrenW32/Threat-SysVenFak-based!Maxi
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTrojan.Win32.ZEGOST.B
AvastWin32:Malware-gen
GDataTrojan.GenericKD.41267737
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Skeeyah.7f23767b
NANO-AntivirusTrojan.Win32.Webmoner.elfdg
ViRobotTrojan.Win32.Z.Agent.149052
Ad-AwareTrojan.GenericKD.41267737
SophosMal/Behav-398
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
F-SecureTrojan.TR/Dldr.Agent.olsko
DrWebTrojan.DownLoader23.39271
ZillyaDownloader.Delf.Win32.57578
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Virut.cc
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.41267737
EmsisoftTrojan.GenericKD.41334844 (B)
APEXMalicious
F-ProtW32/SysVenFak.A.gen!Eldorado
JiangminTrojan.Generic.dmfkw
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.olsko
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D275B219
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Small
AhnLab-V3Trojan/Win32.Agent.R263235
Acronissuspicious
ALYacTrojan.Downloader.Small
MAXmalware (ai score=100)
VBA32suspected of Trojan.Downloader.gen.h
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CJD
YandexTrojan.Agent!0KflZMsdvzw
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Skeeyah.F599!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM17.0.1905.Malware.Gen

How to remove Mal/Behav-398?

Mal/Behav-398 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment