Malware

Mal/Generic-R + Mal/Dropper-O removal guide

Malware Removal

The Mal/Generic-R + Mal/Dropper-O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Dropper-O virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Mal/Generic-R + Mal/Dropper-O?


File Info:

name: 9C48FE26696B7994DD6F.mlw
path: /opt/CAPEv2/storage/binaries/165885e2c5ff2a43861014252a05d6725921f4abceae2531f9590c716493fa34
crc32: E48A9CC2
md5: 9c48fe26696b7994dd6f062dc6fe50b8
sha1: 22715145f12ec6f80688706466039d8fec1d572e
sha256: 165885e2c5ff2a43861014252a05d6725921f4abceae2531f9590c716493fa34
sha512: eaacb3a9cc3b97428c4d1fc9d73a13c8dffc6405e0cfa717b6e9bc344529eec6493ff9f916898642c44cdd9d5412066421909cccbc2429ed6679655464e45017
ssdeep: 192:nEysPjOjmrqTRXvpMAsFBm9wkfd4orJlqpIdguFPNHPuTAxvwCMrpY7e8LqPZo56:ZF+Jk14rwguwAxvr6+e9Pfqbn1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5629D43DF9495F7D0C224B345EBAC258E3BD83185730A2BA3F2816F2D46628EC9C957
sha3_384: e413872fefe49d774e08cfda4827101a6fb668596d98dff789e57fda0010db735019fd240466d2882756725e31017bf1
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2014-05-15 21:33:40

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Dropper-O also known as:

FireEyeGeneric.mg.9c48fe26696b7994
CAT-QuickHealHackTool.TBE.S177314
McAfeeArtemis!9C48FE26696B
CylanceUnsafe
Cybereasonmalicious.5f12ec
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/HackTool.Patcher.JO potentially unsafe
SUPERAntiSpywareTrojan.Agent/Generic
McAfee-GW-EditionBehavesLike.Win32.Dropper.lh
SophosMal/Generic-R + Mal/Dropper-O
APEXMalicious
Antiy-AVLTrojan/Generic.ASMalwS.4E2E7F
MicrosoftPUA:Win32/Presenoker
YandexTrojan.GenAsa!ZnCA9Z6xwgc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
WebrootW32.Malware.Gen

How to remove Mal/Generic-R + Mal/Dropper-O?

Mal/Generic-R + Mal/Dropper-O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment