Malware

Mal/Generic-R + Mal/Emogen-F malicious file

Malware Removal

The Mal/Generic-R + Mal/Emogen-F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Emogen-F virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Mal/Emogen-F?


File Info:

crc32: AE3CA292
md5: e296966d9fdfdec22af2b2e1e15b4c23
name: E296966D9FDFDEC22AF2B2E1E15B4C23.mlw
sha1: 7fff3b8b570e9d844ccf76b7261cbcc54d65b558
sha256: ce1913cc55226672d9496b82787afd475cbbbcc6f21f8aaab94458fe6a64cd48
sha512: 673876bc6661cb12d2a5d05ceceed9efddf349b23dd86aed24e1c11a529a6bf59f5b8053de9d36907aaf3b6b948f285748a2f24d3bc5bdfcbb66350cb0eb4918
ssdeep: 768:XXD4czXlWn1T62dHi1f+li+MA2HG/I0w:s+Vu62dHcA2Ys
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: http://hi.baidu.com/creep345
InternalName: SET_AHK
FileVersion: 1.06
CompanyName: creep345
Comments: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(SET-AHK)
ProductName: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(SET-AHK)
ProductVersion: 1.06
FileDescription: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(SET-AHK)
OriginalFilename: SET_AHK.exe

Mal/Generic-R + Mal/Emogen-F also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Dropper.Gamehack-7085915-0
AlibabaRiskware:Win32/Generic.f2f561f7
NANO-AntivirusTrojan.Win32.Symmi.egxbrz
SophosMal/Generic-R + Mal/Emogen-F
ComodoMalware@#2cfj3r7jqhrsy
McAfee-GW-EditionBehavesLike.Win32.Trojan.mc
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Heur.Dkvt
Antiy-AVLTrojan/Win32.Tgenic
MicrosoftTrojan:Win32/Ymacco.AACE
GridinsoftTrojan.Win32.Agent.dg
AegisLabTrojan.Win32.Generic.4!c
McAfeeRDN/Autorun.worm.gen
VBA32Trojan.Dynamer
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingTrojan.Casur!8.10E51 (CLOUD)
IkarusTrojan-PWS.Win32.VB
eGambitUnsafe.AI_Score_99%

How to remove Mal/Generic-R + Mal/Emogen-F?

Mal/Generic-R + Mal/Emogen-F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment