Malware

Mal/Generic-R + Mal/EncPk-ANQ malicious file

Malware Removal

The Mal/Generic-R + Mal/EncPk-ANQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/EncPk-ANQ virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Mal/EncPk-ANQ?


File Info:

name: 0075D97C5ABD676E1B48.mlw
path: /opt/CAPEv2/storage/binaries/1e3cba548f193059c58fa418a5d5fb7e7ded5c0cb4b1dbfe1f1ea801dcb9efb1
crc32: B2CEDE5F
md5: 0075d97c5abd676e1b4832c4801333e3
sha1: 3ec9597767b73c47cf76dbe735f4a9e0c1cb57b6
sha256: 1e3cba548f193059c58fa418a5d5fb7e7ded5c0cb4b1dbfe1f1ea801dcb9efb1
sha512: a541ff22180272004590bebbf1e437105001907ac4713652e087e9033e333ddd1f75363bc5edf92b3abab4dde00e50c514bcd23c98ecc1f36c3bb2b4c6f119f8
ssdeep: 6144:CWEVsg4rHrCFfMEjxxJ/5YPEn+eiSiku9bBwb4z:m+mFfxb5YMn+ZkaG4z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FB4E1C146529227CD4914B8538FFA2E842F7F00E03DA9B877C557D9A279C8503EBDAB
sha3_384: 37de5088285a252a4d2823fa5aa0790822c900ab645e640574b7f6198d82865c06837bf6cebd87083d9035c7d5c28a36
ep_bytes: 60be00204000908dbe00f0ffffc78708
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Generic-R + Mal/EncPk-ANQ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
DrWebTrojan.Packed2.39727
MicroWorld-eScanGen:Trojan.Heur.EmW@vDTexilin
FireEyeGeneric.mg.0075d97c5abd676e
CAT-QuickHealTrojan.Upantix.AL3
McAfeePacked-KS!0075D97C5ABD
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0050a9591 )
K7AntiVirusTrojan ( 0050a9591 )
BitDefenderThetaAI:Packer.1C39AF021D
CyrenW32/Kryptik.CEA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Kryptik.FKSZ.Gen
TrendMicro-HouseCallTROJ_GEN.R007C0PA122
Paloaltogeneric.ml
KasperskyHEUR:Packed.Win32.Upantix.gen
BitDefenderGen:Trojan.Heur.EmW@vDTexilin
NANO-AntivirusTrojan.Win32.Upantix.ekofiv
TencentMalware.Win32.Gencirc.10b40470
Ad-AwareGen:Trojan.Heur.EmW@vDTexilin
SophosMal/Generic-R + Mal/EncPk-ANQ
ComodoPacked.Win32.MUPX.Gen@24tbus
BaiduWin32.Trojan.Kryptik.bfw
TrendMicroTROJ_GEN.R007C0PA122
McAfee-GW-EditionBehavesLike.Win32.Pluto.gc
EmsisoftGen:Trojan.Heur.EmW@vDTexilin (B)
GDataGen:Trojan.Heur.EmW@vDTexilin
AviraTR/Crypt.ULPM.Gen7
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Malware-Cryptor.General.3
MAXmalware (ai score=80)
PandaTrj/CI.A
APEXMalicious
RisingTrojan.Kryptik!1.A862 (RDMK:cmRtazrAj2aKrX9ziJAAwG+Op+Ff)
YandexTrojan.Kryptik!w5Ae9atNi7c
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bundpil.72F8!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Mal/Generic-R + Mal/EncPk-ANQ?

Mal/Generic-R + Mal/EncPk-ANQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment