Malware

Mal/Generic-R + Mal/GandCrypt-A malicious file

Malware Removal

The Mal/Generic-R + Mal/GandCrypt-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/GandCrypt-A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

How to determine Mal/Generic-R + Mal/GandCrypt-A?


File Info:

crc32: 1013B063
md5: a1e2c8d923e8c729cc5b94379cd1ecbd
name: A1E2C8D923E8C729CC5B94379CD1ECBD.mlw
sha1: f6bd59d6acd21ee074a0fd60e0b18cc3456bea1c
sha256: 66cbc28deafec6b425227711a760c8edd51cb84ad00d55118285d8a1990d59e7
sha512: 5cd614ee54c34aed6059b8dd398df650b08aaa9d97ed94af37d0ff50fb2d11d86415741de755f7c5385db23cdad388885d30c6b9e3380125db381d8c66e04e5f
ssdeep: 12288:GxSyTWObUSO8s99FTGwOfzEcBBdBk9nzyXI+Dy3XHLZl/9z0D+g9WQaK:aSawBBTgfzECBdk81y331lNgYQaK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.5.8.28
FileVerus: 1.0.2.27
Translations: 0x0126 0x0230

Mal/Generic-R + Mal/GandCrypt-A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003e58dd1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Glupteba
ALYacTrojan.GenericKDZ.73607
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Glupteba.71ea0b41
K7GWRiskware ( 0040eff71 )
ESET-NOD32a variant of Win32/Kryptik.HKAW
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKDZ.73607
MicroWorld-eScanTrojan.GenericKDZ.73607
Ad-AwareTrojan.GenericKDZ.73607
SophosMal/Generic-R + Mal/GandCrypt-A
ComodoTrojWare.Win32.UMal.gxrnw@0
BitDefenderThetaGen:NN.ZexaF.34628.GqW@aCLpm8iG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.a1e2c8d923e8c729
EmsisoftTrojan.GenericKDZ.73607 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Glupteba.qpzoc
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.PG!MTB
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataTrojan.GenericKDZ.73607
AhnLab-V3CoinMiner/Win.Glupteba.R373266
McAfeePacked-GDK!A1E2C8D923E8
MAXmalware (ai score=84)
VBA32Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06EC0DCO21
RisingMalware.Obscure/Heur!1.A89F (CLOUD)
IkarusTrojan-Banker.UrSnif
MaxSecureTrojan.Malware.73643692.susgen
FortinetW32/GenKryptik.FDFQ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Chapak.HwoCBeMA

How to remove Mal/Generic-R + Mal/GandCrypt-A?

Mal/Generic-R + Mal/GandCrypt-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment