Malware

Mal/Generic-R + Mal/Agent-AUL removal tips

Malware Removal

The Mal/Generic-R + Mal/Agent-AUL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Agent-AUL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Mal/Generic-R + Mal/Agent-AUL?


File Info:

crc32: 2EE27D67
md5: 062ffdb91d0a9225b6e67bc8cd693e55
name: 062FFDB91D0A9225B6E67BC8CD693E55.mlw
sha1: 19a997021a1a0826197660b6397ee39f3e36209b
sha256: 4d2ccc4caae340851248ef43f63fd572626e11610196e84875325f49de84fdc2
sha512: 45a24c638b3c4b8fcd80887e3d2e8ded5c32c5340807d441774890deaf62963248ac0432a1c5684caaa31077b251848d328d61a952078f60a16731dfbae904f3
ssdeep: 6144:U2WiLHnbFDm4K/fkSH0/BJkqW35aYDI9X:U2TTnbVpK/Mxvi3TI9X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Agent-AUL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.062ffdb91d0a9225
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.GandCrypt.j!c
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.91d0a9
BitDefenderThetaGen:NN.ZexaF.34590.uuX@a4!AkT
CyrenW32/S-57da8aa8!Eldorado
SymantecPacked.Generic.525
ESET-NOD32Win32/Filecoder.GandCrab.B
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.NeutrinoPOS.fcgsxu
ViRobotTrojan.Win32.GandCrab.Gen.A
TencentMalware.Win32.Gencirc.10b4924a
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
SophosMal/Generic-R + Mal/Agent-AUL
ComodoTrojWare.Win32.Magniber.BF@7nq2ts
F-SecureHeuristic.HEUR/AGEN.1102735
DrWebTrojan.DownLoader26.46657
ZillyaTrojan.Kryptik.Win32.1422370
TrendMicroRansom_GANDCRAB.SMJS2
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.db
AviraHEUR/AGEN.1102735
Antiy-AVLTrojan[Banker]/Win32.NeutrinoPOS
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AhnLab-V3Win-Trojan/Gandcrab.Exp
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
Acronissuspicious
McAfeeTrojan-FPPS!062FFDB91D0A
MAXmalware (ai score=99)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMJS2
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GandCrypt!INLNoSgP1DQ
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.a33

How to remove Mal/Generic-R + Mal/Agent-AUL?

Mal/Generic-R + Mal/Agent-AUL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment