Malware

What is “Win32:ReposFxg-F [Trj]”?

Malware Removal

The Win32:ReposFxg-F [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:ReposFxg-F [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid

Related domains:

n73fu7.wayout.pictures
www.jmxyc.com
UxEoYd.yXsQPaPeZTaIQLwjCfnh.readme.io
idcomercial.com.br
noscullsnow.com
AwZLufu.VQvTGPfLjUcMuheBrxPk.readme.io
gxLbZMeldqyYtU.NEznaNoMiSjfJAerXOJQ.readme.io
kyNSsYdlTdw.sRWRBjaCQQteOMIRsYIo.readme.io
rTxDffM.zMRugFegaMweCVDlmdsZ.readme.io
zDCQ.GmCNXflqOgAYQGDxJLhO.readme.io
kFvs.mkFGEcafJnrohlvgttAy.readme.io
kampower.com
mega.nz
PfGjCmKcIKx.zurYoBpCVKFubuBHsVMN.readme.io
o.vBYhbFMCWwDmqlTEKaLq.readme.io
xjOH.YdTsppzxDitzYtZmljdl.readme.io
aNIBy.VxjHsgISrYZtUFaRVEEO.readme.io
dxpFSF.NDFnkVWPZhBpnHoLawEJ.readme.io
njJsXwn.GjyEdIsaUSjDsskLNchv.readme.io
LRHYPFMVXkRi.tSJAMXEEGQuBFUteFMNK.readme.io
eyi.qEbzsnSxEuiJjTdhfkkI.readme.io
ghdK.fMasNJSCLDmEfDOgyACc.readme.io
raw.githubusercontent.com
ztsdeNqsGDQYzE.drQIVHGtYdiemdNHYMKf.readme.io
tLbhhUIzVEx.swMbIYgGxjWvClyTHqLr.readme.io
ufNETryfcgU.RTKHezuZoxhtzCDMfYse.readme.io
XeZnKaKY.HguaPEoOElJtONzEZZIP.readme.io
WlvdHOVavOjkH.EwBToYzMVOfRhkTVoOzI.readme.io
yZNFY.QuCUNlrKMDpmkgapHEBp.readme.io
XyzfKt.bitbucket.com
Rtlcy.bitbucket.com
MAzhGRmPSM.bitbucket.com
j.gqSZvJjAkbqsuCkMXgWJ.readme.io
xzNCDBE.SlFMOrTWBrvWzqdNsuMO.readme.io
www.dropbox.com
QoFIaqPl.bitbucket.com
RvSZ.bitbucket.com
cjyQ.bitbucket.com
BqmCVNLdZjng.bitbucket.com
vLK.bitbucket.com
mHI.bitbucket.com
FCS.bitbucket.com
zZRcZRYsoAmQB.bitbucket.com
www.bates.edu
jmbvmwp.mxp4037.com
mDuIQEnUc.vTpakBmmDfBqZKecSXQr.readme.io
PFrnd.JjyfgiqkkjXwqviWRQOg.readme.io
KtNBnhm.GjCdbcyPkALsnLkHeMPn.readme.io
AtA.OslTgowbDRLgZgvIPxDW.readme.io
AjsKnrVILoYMOo.uMYFQlabxAgbymYCpyPY.readme.io
NAxBJtTIwZ.LysrFhizYdWvAXNpaYbt.readme.io
EuBGccoP.jbjhpmaypqyCgYZDhlYB.readme.io
oTvFfbIBqdbDPn.mIRDeXxdbeImHlJLCwRu.readme.io
XaULtsCbsS.AYHwbHjfvlXkWqYtBrwK.readme.io
ERjouAxQ.URVgzVjqLCqKsKMFhjAM.readme.io
ZwKuPD.zcyBqaqzCQogSCbBDrzD.readme.io
nbJWdnRF.LvyFhmlDTiwILmKoztKS.readme.io
rCMLUtSgRWh.JvaxUZVsZXIWzmUzdENK.readme.io
D.BJAQopyqDATQEXfmpuBb.readme.io
DOlf.bJDFUVeVoqSFfWOySoum.readme.io
BWesKoW.hgOljlUsLJhKvkBSDHUp.readme.io
PRokfhBMsdzkc.KgdOCAyqmtjOdVPvFyvn.readme.io
UGVMIsW.uhEZWxRQjyqqZXeQttyh.readme.io
ZbP.RzocFTPoVsepfBMftTWU.readme.io
oCfmTRpIY.oMMXEWjVrdHdaNbAxXWt.readme.io
K.bAjvfCSCCLIxKUoYHnQJ.readme.io
Zi.idJIglohxWxmsNqMtCqC.readme.io
DBfZQcXnXxOe.PVBjcZohPWJpEIwYINdz.readme.io
qDhqZtNL.KmDymnOYMsfNElIyUMHU.readme.io

How to determine Win32:ReposFxg-F [Trj]?


File Info:

name: 6990598DD77D11F20393.mlw
path: /opt/CAPEv2/storage/binaries/c21b430a24295d8e84b9713183446f83948e0bab76ea60f29d4bca263ee5d649
crc32: C161A92C
md5: 6990598dd77d11f2039362758d0400be
sha1: b623b1fb03b94ab4a61877a729025f6e484a98d1
sha256: c21b430a24295d8e84b9713183446f83948e0bab76ea60f29d4bca263ee5d649
sha512: c15cf1ccf92b2ba1a2e3464ed9bf7098a238556d5d087713b22e891eb815be31929ac53f411ae70745883aa20b6b8f47adfffcbc0358c00523a37abbeca9f5cc
ssdeep: 49152:2WkGiEcNuZpL0HBTT8b+rjjYvr/r9V6kbjOtUsNXtyeKdkuv04xjjBqOH2OwggZF:2jGZKRbj0z/rHrOPN9GtxjNqa2qIvkM
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1AFE533A93DB5E8A1D0ABB53E7241CA3876B12475DC01A70033B56FD8299172FE29DF07
sha3_384: cf19cb4b51e2e0c6a92e5889d2521f8f94b743c4db3e01bf2490dddcf619257e9b00631645258fe33f16932ba4e88196
ep_bytes: 53565755488d35fa38d2ff488dbedbaf
timestamp: 2019-12-07 10:51:21

Version Info:

0: [No Data]

Win32:ReposFxg-F [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.60758
FireEyeGeneric.mg.6990598dd77d11f2
ALYacTrojan.GenericKDZ.60758
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e5891 )
K7GWTrojan ( 0055e5891 )
Cybereasonmalicious.dd77d1
CyrenW64/Kryptik.BDT.gen!Eldorado
ESET-NOD32a variant of Win64/Filecoder.A
APEXMalicious
ClamAVWin.Malware.Tofsee-7057860-0
KasperskyWorm.Win64.AutoRun.m
BitDefenderTrojan.GenericKDZ.60758
AvastWin32:ReposFxg-F [Trj]
RisingTrojan.Kryptik!1.C31C (CLASSIC)
Ad-AwareTrojan.GenericKDZ.60758
EmsisoftApplication.Miner (A)
DrWebWin32.HLLO.Siggen.8
TrendMicroRansom.Win64.PORNOASSET.SM1.hp
McAfee-GW-EditionBehavesLike.Win64.Trickbot.wc
SophosML/PE-A + Mal/HckPk-R
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.60758
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C626
ArcabitTrojan.Generic.DED56
MicrosoftTrojan:Win32/SmokeLoader
CynetMalicious (score: 100)
AhnLab-V3Win64-Trojan/Pakes.Exp
Acronissuspicious
McAfeeTrickbot-FRE!6990598DD77D
MAXmalware (ai score=88)
VBA32Trojan.Win64.Pakes
MalwarebytesMalware.AI.1627480902
TrendMicro-HouseCallRansom.Win64.PORNOASSET.SM1.hp
YandexTrojan.GenAsa!csWrS4OGpG4
IkarusTrojan.LockyC
FortinetW64/Kryptik.BTT!tr
BitDefenderThetaGen:NN.ZexaF.34294.luW@aq5RFHdi
AVGWin32:ReposFxg-F [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Win32:ReposFxg-F [Trj]?

Win32:ReposFxg-F [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment