Malware

Mal/Generic-R + Mal/Miner-H information

Malware Removal

The Mal/Generic-R + Mal/Miner-H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Miner-H virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Mal/Generic-R + Mal/Miner-H?


File Info:

name: 006E96C05A09E0A99B66.mlw
path: /opt/CAPEv2/storage/binaries/8c383f415dfcf96dd473d7a239a4315cdec3e502c1c9a6bf5cf9ad3d5e2f6f4a
crc32: D04CEC7C
md5: 006e96c05a09e0a99b6642576682029b
sha1: 150e7836143a8e79b8355ed7072cdc33b43cc734
sha256: 8c383f415dfcf96dd473d7a239a4315cdec3e502c1c9a6bf5cf9ad3d5e2f6f4a
sha512: f436ae348e31d33debb344b16906e5e9c8d32611478c22e2126680d8476ddd253b7e79cb8852961619c5b6030296396760f586ccd846af2aecb23448761931d4
ssdeep: 98304:CLFPs+IH5oB68bfqYPTfSQGwCWeHprHYZwGzSRCOa7b2:ols3oBFdLSQPijYaGuDa7y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105363392A8C1C3B6D6B11E748124A714777A7C112B18DEAFE3D46E0FD670192BB30B67
sha3_384: 3afd50c6b57a089d5026a380547ddaadcb8854fddaa574f54a19ed65d90812c9d3558ecca833aeea489a951756cd9255
ep_bytes: e8a4040000e988feffff3b0d68e64300
timestamp: 2021-04-07 14:39:21

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Miner-H also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.37042838
FireEyeTrojan.GenericKD.37042838
McAfeeArtemis!006E96C05A09
MalwarebytesTrojan.Dropper
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 004a9a8f1 )
AlibabaTrojan:RAR/Miner.685dcb57
K7GWTrojan ( 004a9a8f1 )
ArcabitTrojan.Generic.D2353A96
ESET-NOD32RAR/Agent.AP
TrendMicro-HouseCallTROJ_GEN.R002C0RHJ21
ClamAVWin.Malware.Generic-9869236-0
BitDefenderTrojan.GenericKD.37042838
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.37042838
SophosMal/Generic-R + Mal/Miner-H
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RHJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.GenericKD.37042838 (B)
IkarusPUA.CoinMiner
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.37042838
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37042838
CylanceUnsafe
APEXMalicious
TencentWin32.Trojan.Agent.Chq
MAXmalware (ai score=85)
eGambitUnsafe.AI_Score_100%
FortinetRiskware/CoinMiner
AVGWin32:Trojan-gen

How to remove Mal/Generic-R + Mal/Miner-H?

Mal/Generic-R + Mal/Miner-H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment