Malware

How to remove “Mal/Generic-R + Mal/EncPk-AGX”?

Malware Removal

The Mal/Generic-R + Mal/EncPk-AGX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/EncPk-AGX virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Mal/EncPk-AGX?


File Info:

crc32: 41B573A3
md5: 0c652c1ab2c17aa18527ab4e59f12478
name: 0C652C1AB2C17AA18527AB4E59F12478.mlw
sha1: 8af4ece97c65bcbfef6b7fd04506c76270f2f0ce
sha256: ccfc333c865efbcf17dfd46e3fe7576467d5561d34fa7438b9e04bd0e768ed22
sha512: 0093c6a1a1ca243918026441b7edd68a7ea2f3951787a399707a254e7793c04da4ecf1d826e04e5a8914ed4506d683acff9d946f66ebf4ba84ace43ce1b95ec1
ssdeep: 3072:bY1tnGVUymCz0irxE2Lm4y0tfWXb2R9JnP1mpGR1AY:bY1tGuymGxdy0tfW69zR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Mal/EncPk-AGX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0003868d1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
CynetMalicious (score: 100)
ALYacGen:Heur.VIZ.5
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.77320
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:Win32/EncPk.93ceddaf
K7GWSpyware ( 0003868d1 )
Cybereasonmalicious.ab2c17
CyrenW32/Zbot.IZ.gen!Eldorado
SymantecTrojan.Ransomlock!g9
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
AvastWin32:Cryptor
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.5
NANO-AntivirusTrojan.Win32.Zbot.bffbpm
MicroWorld-eScanGen:Heur.VIZ.5
TencentMalware.Win32.Gencirc.114d6c9a
Ad-AwareGen:Heur.VIZ.5
SophosMal/Generic-R + Mal/EncPk-AGX
ComodoMalware@#1u3k8154wendt
BitDefenderThetaAI:Packer.71BF286C1E
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroTROJ_RANSOM.SMJO
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
FireEyeGeneric.mg.0c652c1ab2c17aa1
EmsisoftGen:Heur.VIZ.5 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.cfqu
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen8
eGambitGeneric.Malware
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftPWS:Win32/Zbot!CI
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Heur.VIZ.5
AhnLab-V3Spyware/Win32.Zbot.R42223
Acronissuspicious
McAfeePWS-Zbot.gen.ano
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Oop
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.SMJO
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!eJskJ1EKz8g
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Sasfis.ANO!tr
AVGWin32:Cryptor
Paloaltogeneric.ml

How to remove Mal/Generic-R + Mal/EncPk-AGX?

Mal/Generic-R + Mal/EncPk-AGX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment