Ransom

Mal/Generic-R + Mal/Ransom-AI removal tips

Malware Removal

The Mal/Generic-R + Mal/Ransom-AI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Ransom-AI virus can do?

  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Mal/Ransom-AI?


File Info:

crc32: F3E62709
md5: 409ad7ed76874dd4e546cfc413d94761
name: 409AD7ED76874DD4E546CFC413D94761.mlw
sha1: e79fe823414d502b3b750ff39eebf8e56cc64e62
sha256: f7f6699eb3376d10acc32bbc4ee98ea0525c3e6bc8497647ca36be6e11101657
sha512: 751bcb7d857ce8d5d860d6e635609d1bfd159296588df765ba74477a8882d760a08d69def91ed8d398faa43d63ead9f684aa99dc7ab72958a9ee70159208fa28
ssdeep: 3072:dGbHwx3GsAFyQbXO0kwXmFRqAh+7QouCv8BATTy+zL9GwqRlcBapeEdmIMyX:dG7u6jrkwvKaXR0cyYLF6lcBapBdd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Ransom-AI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.5848174
FireEyeGeneric.mg.409ad7ed76874dd4
CAT-QuickHealRansom.Weenloc.A8
McAfeeGenericRXAA-AA!409AD7ED7687
CylanceUnsafe
VIPRETrojan.Win32.Birele.mby (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0039911e1 )
BitDefenderTrojan.Generic.5848174
K7GWTrojan ( 0039911e1 )
Cybereasonmalicious.d76874
BitDefenderThetaGen:NN.ZelphiF.34590.jmGfaWBFNzoI
CyrenW32/Trojan.GDVD-7096
SymantecTrojan.Ransomlock
TotalDefenseWin32/Ransom.BAM
BaiduWin32.Trojan.LockScreen.b
APEXMalicious
AvastWin32:LockScreen-AHV [Trj]
ClamAVWin.Ransomware.Fullscreen-7347612-0
KasperskyTrojan-Ransom.Win32.Blocker.jzec
AlibabaRansom:Win32/Blocker.cf60847d
NANO-AntivirusTrojan.Win32.Fullscreen.crnep
TencentTrojan-Ransom.Win32.Blocker.jzec
Ad-AwareTrojan.Generic.5848174
TACHYONRansom/W32.DP-PornoAsset.407040
EmsisoftTrojan.Generic.5848174 (B)
ComodoTrojWare.Win32.Ransom.Fullscreen.fgt@4t6ar8
F-SecureDropper.DR/Delphi.Gen4
DrWebTrojan.Winlock.3333
ZillyaTrojan.Fullscreen.Win32.36
TrendMicroRansom_WINLOCK.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SophosMal/Generic-R + Mal/Ransom-AI
JiangminTrojan/Fullscreen.ak
AviraDR/Delphi.Gen4
Antiy-AVLTrojan[Ransom]/Win32.PornoAsset.cioy
KingsoftHeur.SSC.5536.1216.(kcloud)
ArcabitTrojan.Generic.D593C6E
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
ZoneAlarmTrojan-Ransom.Win32.Blocker.jzec
GDataTrojan.Generic.5848174
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Winlock.C134008
VBA32TScope.Trojan.Delf
MAXmalware (ai score=81)
MalwarebytesRansom.Filecoder
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/LockScreen.AGU
TrendMicro-HouseCallRansom_WINLOCK.SM
RisingTrojan.Win32.Weenloc.a (CLOUD)
YandexTrojan.GenAsa!EkA5wRxKoJY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/LockScreen.AGU!tr
AVGWin32:LockScreen-AHV [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Ransom.Blocker.HwsBqGUA

How to remove Mal/Generic-R + Mal/Ransom-AI?

Mal/Generic-R + Mal/Ransom-AI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment