Malware

Mal/Generic-R + ATK/Mimikatz-BE removal

Malware Removal

The Mal/Generic-R + ATK/Mimikatz-BE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + ATK/Mimikatz-BE virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Mal/Generic-R + ATK/Mimikatz-BE?


File Info:

crc32: 3AC54D12
md5: 0bef1dcd9dd6080717348c6f31408815
name: 0BEF1DCD9DD6080717348C6F31408815.mlw
sha1: 310cb25aeb0d924eb48e996a6307aef481052be5
sha256: 6f754e9030c410441971774fbba1df43b902482fc09961f04122ccad1683b39d
sha512: e0afc3416d75923847e81f92f31284fbf8c045a52209ed90510c4c476fbca6fdbaeaa17ad2afc6eec479fa2aa70d4e47cedd8dc416fe321e2fc8c47e376c2985
ssdeep: 12288:C3HA6hvOf/j5WkkO69sH61UgOIGwNUBWYL59Jzm3Qi2i3Jm9RNDUSxzxD:qA0ab53kO69M2OWgpm3Q7o6z
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2007 - 2020 xiaozhanniubi (Benjamin DELPY)
InternalName: cxkniubi
FileVersion: 2.2.0.0
CompanyName: xiaozhanniubi (Benjamin DELPY)
PrivateBuild: Build with love for POC only
ProductName: cxkniubi
SpecialBuild: :)
ProductVersion: 2.2.0.0
FileDescription: cxkniubi for Windows
OriginalFilename: cxkniubi.exe
Translation: 0x0409 0x04b0

Mal/Generic-R + ATK/Mimikatz-BE also known as:

K7AntiVirusTrojan ( 004f6bc61 )
CynetMalicious (score: 100)
ALYacGen:Heur.Mimikatz.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaHackTool:Win64/Mimikatz.ce44b247
K7GWTrojan ( 004f6bc61 )
Cybereasonmalicious.d9dd60
CyrenW64/Trojan.XUJI-0812
SymantecInfostealer!im
ESET-NOD32a variant of Win64/Riskware.Mimikatz.D
APEXMalicious
AvastWin64:Malware-gen
KasperskyHEUR:Trojan-PSW.Win64.Mimikatz.gen
BitDefenderGen:Heur.Mimikatz.1
MicroWorld-eScanGen:Heur.Mimikatz.1
TencentWin64.Trojan-qqpass.Qqrob.Jmt
Ad-AwareGen:Heur.Mimikatz.1
SophosMal/Generic-R + ATK/Mimikatz-BE
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R005C0RG121
McAfee-GW-EditionBehavesLike.Win64.Generic.bc
FireEyeGeneric.mg.0bef1dcd9dd60807
EmsisoftGen:Heur.Mimikatz.1 (B)
SentinelOneStatic AI – Malicious PE
eGambithacktool.mimikatz
Antiy-AVLTrojan/Generic.ASBOL.C5E3
MicrosoftHackTool:Win64/Mimikatz.gen!G
AegisLabTrojan.Win64.Mimikatz.i!c
ZoneAlarmHEUR:Trojan-PSW.Win32.Mimikatz.gen
GDataGen:Heur.Mimikatz.1
McAfeeArtemis!0BEF1DCD9DD6
MAXmalware (ai score=85)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0RG121
FortinetAdware/Mimikatz
AVGWin64:Malware-gen
Qihoo-360Win64/HackTool.Mimikatz.HgEASXoA

How to remove Mal/Generic-R + ATK/Mimikatz-BE?

Mal/Generic-R + ATK/Mimikatz-BE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment