Malware

About “Mal/Generic-R + Mal/Qbot-P” infection

Malware Removal

The Mal/Generic-R + Mal/Qbot-P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Qbot-P virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

edgedl.gvt1.com

How to determine Mal/Generic-R + Mal/Qbot-P?


File Info:

crc32: 5CF4905D
md5: 827332779369d86543dacf4ee7aa7a12
name: 827332779369D86543DACF4EE7AA7A12.mlw
sha1: 5f863a934f0878a9dc1efb876e21e4b8b36e6162
sha256: b9188e43edd76a1077898e0b4c273edc89d2992bc3f39fd7f5bf815d9242db41
sha512: 46e5ea402987b66581697e42da442fe1cf90cd7ad33f31ad1d8ea6f3f8e8def61cbfa2607f5572f5e12a4e00382603a9d5c67ce2097d6e91d892f43220272962
ssdeep: 6144:TcwnEVqsna9sPaY/hxibXjv5NPkdIWCMPYVZSU4faARSlXX1:7EMsnaUGX1NPajCMP+Z2filXX1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xffa9 Microsoft Corporation. All rights reserved.
InternalName: IEUDINIT
FileVersion: 7.00.5730.13
CompanyName: Microsoft Corporation
PrivateBuild: IEUDINIT.EXE
LegalTrademarks: xffa9 Microsoft Corporation. All rights reserved.
Comments:
ProductName: Windowsxffae Internet Explorer
SpecialBuild: 7.00.5730.13
ProductVersion: 7.00.5730.13
FileDescription: IE Per User Active Setup Uninstall Utility
OriginalFilename: IEUDINIT.EXE
Translation: 0x0409 0x04b0

Mal/Generic-R + Mal/Qbot-P also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Malware.xu0@aydV0Dmi
FireEyeGeneric.mg.827332779369d865
CAT-QuickHealTrojan.Small.gen
ALYacGen:Trojan.Malware.xu0@aydV0Dmi
MalwarebytesMalware.AI.408324201
VIPRETrojan.Win32.Small.bhm (v)
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Trojan.Malware.xu0@aydV0Dmi
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.79369d
BitDefenderThetaGen:NN.ZexaF.34590.xu0@aydV0Dmi
CyrenW32/SmallDl.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
NANO-AntivirusTrojan.Win32.Ezula.byfcsh
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Trojan.Malware.xu0@aydV0Dmi
EmsisoftGen:Trojan.Malware.xu0@aydV0Dmi (B)
ComodoTrojWare.Win32.Agent.AWR@4ri3wg
F-SecureTrojan.TR/Small.bhouma
DrWebAdware.Ezula.4461
ZillyaTrojan.Rodecap.Win32.2197
TrendMicroTROJ_RODECAP.SMO
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosMal/Generic-R + Mal/Qbot-P
IkarusTrojan.Win32.Small
eGambitUnsafe.AI_Score_92%
AviraTR/Small.bhouma
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Malware.EEACFF
GDataGen:Trojan.Malware.xu0@aydV0Dmi
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.R52075
Acronissuspicious
McAfeeGenericRXGF-ZN!827332779369
VBA32BScope.Adware.Ezula
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Rodecap.BB
TrendMicro-HouseCallTROJ_RODECAP.SMO
TencentMalware.Win32.Gencirc.10b682c4
YandexTrojan.GenAsa!6KhuQuHc76g
SentinelOneStatic AI – Suspicious PE
FortinetW32/Rodecap.BBC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.2.7C4C.Malware.Gen

How to remove Mal/Generic-R + Mal/Qbot-P?

Mal/Generic-R + Mal/Qbot-P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment