Malware

Mal/Generic-R + Mal/EncPk-AIT removal guide

Malware Removal

The Mal/Generic-R + Mal/EncPk-AIT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/EncPk-AIT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Collects information to fingerprint the system

How to determine Mal/Generic-R + Mal/EncPk-AIT?


File Info:

name: 367D930B87B5FD004D10.mlw
path: /opt/CAPEv2/storage/binaries/47923a19f41fab90851b6a824fe8b44c1c766c07f67f07219bc8c68ddfb81efa
crc32: D176DD9D
md5: 367d930b87b5fd004d10b685585ae0d1
sha1: 23572e518a1037a482efdf0907b1cff0923628bb
sha256: 47923a19f41fab90851b6a824fe8b44c1c766c07f67f07219bc8c68ddfb81efa
sha512: db71d9912c2d0a9f5dea311382d088e77402769468ba6b96cf93c2402d6baac13fe627dc5a6e6c4196f68a4e6b9d393fd9992bc89cbbf72f150a922205c8c694
ssdeep: 3072:BdgNz8NQQJsQdYCppV19PxSzZj4fVsA8iQPWpj:cVaKqpTMj4VEaj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D349CD3FB5E411EC447E57CDAC788B9848CAC907A163273358FE15E887E652EA3C681
sha3_384: 4d42cf062218aa34464b169206f75ed50e7f774acd36984f58eb15503245039b04a33a9e9307e57df123ad3c757d3618
ep_bytes: 558bec5155c745fc97a00000c745fc97
timestamp: 2013-03-27 05:24:57

Version Info:

0: [No Data]

Mal/Generic-R + Mal/EncPk-AIT also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Redirect.140
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.367d930b87b5fd00
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePWS-Zbot-FATG!367D930B87B5
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.1166
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Kryptik.9e7f1171
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b87b5f
BitDefenderThetaGen:NN.ZexaF.34182.pqX@auP8TVic
VirITTrojan.Win32.Redirect.FK
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.AXPN
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
Paloaltogeneric.ml
ClamAVWin.Ransomware.Cerber-5970165-0
KasperskyTrojan.Win32.ShipUp.bph
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.ShipUp.bqoufa
RisingTrojan.Kryptik!1.AB8B (CLOUD)
TACHYONTrojan/W32.ShipUp.249144
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
BaiduWin32.Trojan.Agent.eq
VIPRETrojan.Win32.Zbot.m (v)
TrendMicroTROJ_KRYPTK.SMAD
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosMal/Generic-R + Mal/EncPk-AIT
IkarusTrojan.Win32.ShipUp
JiangminTrojan/ShipUp.ig
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1313D1
MicrosoftTrojan:Win32/Zbot.SIBL!MTB
ViRobotTrojan.Win32.Z.Kryptik.249144.D
ZoneAlarmTrojan.Win32.ShipUp.bph
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Shipup.R58811
VBA32Trojan.ShipUp
ALYacTrojan.Ransom.Cerber.1
MAXmalware (ai score=84)
MalwarebytesTrojan.ShipUp
PandaTrj/Hexas.HEU
APEXMalicious
TencentTrojan-Ransom.Win32.ShipUp.bph
YandexTrojan.GenAsa!eLqP2To3Rr0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AXRD!tr
AVGWin32:Gepys-J [Trj]
AvastWin32:Gepys-J [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Generic-R + Mal/EncPk-AIT?

Mal/Generic-R + Mal/EncPk-AIT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment