Malware

Mal/Generic-R + Mal/Behav-112 (file analysis)

Malware Removal

The Mal/Generic-R + Mal/Behav-112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Behav-112 virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Mal/Generic-R + Mal/Behav-112?


File Info:

name: 8C7FC87B6E7B20680C71.mlw
path: /opt/CAPEv2/storage/binaries/a44d4524461689be73d923cd4a49d59b075683a79cc1e0310edeb21a2b1de755
crc32: 4B8B9BA2
md5: 8c7fc87b6e7b20680c718d56d2623819
sha1: e156e7c883a9fe10e4e47a2fd79dcffb01a51486
sha256: a44d4524461689be73d923cd4a49d59b075683a79cc1e0310edeb21a2b1de755
sha512: 1295f9e1314ede9f0b763aaa66b84d24c31ce2bce6a60b7619e205ca9d192b2d24fec6568d3d4b4236fd4ade312b9d38451b92ca47be011b565e94161b014d61
ssdeep: 6144:RqNAdxpZBCzQ0YnOU0NqU+TFAEPs86R5oBT/LdCF:OaZBCzQ0YqNqU+TFAEE86R5o9QF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15384D86E0E04DB51E49AB3B0D843A4BE256FC180B7602E9A4FB5E7DC0E7D40AD99DC1D
sha3_384: a5448bd5ebf2287f447553555fc49b116eeb1c433579c2966323d93c81863b2aa26dc2f947b667bf18644fe899bbd6aa
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Behav-112 also known as:

LionicVirus.Win32.Shodi.lzG3
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34110279
FireEyeGeneric.mg.8c7fc87b6e7b2068
CAT-QuickHealW32.Zombie.A4
McAfeeGenericRXNR-SA!8C7FC87B6E7B
CylanceUnsafe
SangforTrojan.Win32.Cosmu.bwts
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0055e3dd1 )
K7AntiVirusTrojan ( 0055e3dd1 )
CyrenW32/Cosmu.H.gen!Eldorado
ESET-NOD32Win32/Agent.NBJ
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Cosmu.bwts
BitDefenderTrojan.GenericKD.34110279
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
TencentVirus.Win32.Cosmu.a
Ad-AwareTrojan.GenericKD.34110279
EmsisoftTrojan.GenericKD.34110279 (B)
ComodoTrojWare.Win32.Agent.NBJ@4xjtww
DrWebTrojan.Encoder.185
VIPRETrojan.Win32.Cosmu.bwts (v)
TrendMicroTROJ_SPNR.15CC13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fm
SophosMal/Generic-R + Mal/Behav-112
JiangminTrojan/Cosmu.ppf
AviraTR/ATRAPS.Gen
KingsoftHeur.SSC.2787082.0010.(kcloud)
ArcabitTrojan.Generic.D2087B47
ViRobotTrojan.Win32.Z.Cosmu.399916
MicrosoftTrojan:Win32/Zombie.A
AhnLab-V3Trojan/Win32.Cosmu.R51515
VBA32Trojan.Cosmu
ALYacTrojan.GenericKD.34110279
MAXmalware (ai score=88)
RisingVirus.Zombie!1.AB2A (CLOUD)
FortinetW32/Agent.NBJ!tr
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen

How to remove Mal/Generic-R + Mal/Behav-112?

Mal/Generic-R + Mal/Behav-112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment