Malware

Should I remove “Mal/Generic-R + Mal/Behav-156”?

Malware Removal

The Mal/Generic-R + Mal/Behav-156 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Behav-156 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Mal/Behav-156?


File Info:

name: ACF8544ACC1315C12ACF.mlw
path: /opt/CAPEv2/storage/binaries/67612b0587c4b2dc07da4e856bc140eba054972bbf6ae6f3dd1bdc697ae5e1b2
crc32: 268504AB
md5: acf8544acc1315c12acf76b1327b3a92
sha1: fc131ad05bc5c8e6b01a2aba3f5caffde5b828dc
sha256: 67612b0587c4b2dc07da4e856bc140eba054972bbf6ae6f3dd1bdc697ae5e1b2
sha512: 71e65a2f67452c7998ad02174b0cfb69dab10a6c45c30977bd66a671f6e789a2576df2aa63e8a33198429de422ef9659a192f98c80229fec5cf1519996168cba
ssdeep: 12288:qb9EkKFFXtIHCjekb9EkKFFXtIHCjekb9EkKFFXtIHCje:q5EFsHC/5EFsHC/5EFsHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCE412E7478561BDCED880340A6F3E6D1757B15E0B680BD0E2D5EABC3E1A30AF891617
sha3_384: 6b8b5f34c7dcaff0ef057315f4febfe0545cd594c3604449b0de0810de1ef17cf4489c60f29033c1f15675f32bf08c58
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Behav-156 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47401452
CAT-QuickHealTrojan.QqpassPMF.S14264295
ALYacTrojan.GenericKD.47401452
CylanceUnsafe
ZillyaTrojan.QQPass.Win32.2179
K7AntiVirusTrojan ( 7000000f1 )
AlibabaWorm:Win32/Fasong.485
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.acc131
BaiduWin32.Trojan-PSW.OLGames.bm
CyrenW32/QQPass.GIFW-2105
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Fasong.I
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Qqpass-172
KasperskyTrojan.Win32.Reconyc.fxms
BitDefenderTrojan.GenericKD.47401452
NANO-AntivirusTrojan.Win32.Reconyc.flewco
AvastWin32:Trojan-gen
RisingTrojan.QPWorkFile (CLASSIC)
Ad-AwareTrojan.GenericKD.47401452
TACHYONTrojan/W32.DP-Reconyc.512000
EmsisoftTrojan.GenericKD.47401452 (B)
DrWebTrojan.PWS.Qqpass
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_SPNR.15CG12
McAfee-GW-EditionBehavesLike.Win32.Autorun.jc
FireEyeGeneric.mg.acf8544acc1315c1
SophosMal/Generic-R + Mal/Behav-156
IkarusTrojan.Small
GDataTrojan.GenericKD.47401452
JiangminTrojan/PSW.QQPass.7002
AviraTR/QQpass.7002
Antiy-AVLTrojan/Generic.ASMalwS.3D9DAB
ArcabitTrojan.Generic.D2D349EC
ViRobotTrojan.Win32.A.PSW-QQPass.221805[ASPack]
MicrosoftPWS:Win32/QQpass.7002
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.QQPass.R57556
McAfeePWS-QQPass
MAXmalware (ai score=84)
VBA32TrojanPSW.QQpass
MalwarebytesMalware.AI.701273177
TrendMicro-HouseCallTROJ_SPNR.15CG12
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!WhueQjJX3a8
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/QQPass.7002!tr
BitDefenderThetaGen:NN.ZelphiF.34294.ROZba8vqhonb
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove Mal/Generic-R + Mal/Behav-156?

Mal/Generic-R + Mal/Behav-156 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment