Malware

How to remove “Mal/Generic-R + Mal/ZboCheMan-L”?

Malware Removal

The Mal/Generic-R + Mal/ZboCheMan-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/ZboCheMan-L virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Spoofs its process name and/or associated pathname to appear as a legitimate process

How to determine Mal/Generic-R + Mal/ZboCheMan-L?


File Info:

name: F02F45EAC24B4CEFD3FE.mlw
path: /opt/CAPEv2/storage/binaries/62f74df0c31e8b7f0b92b47827c180ee58bb11747ada526c0401944a1ef9d8ea
crc32: 54C8043F
md5: f02f45eac24b4cefd3fe176a6e2de9c9
sha1: 00b54017ad9ca2313bb338008d365e4158d5ce72
sha256: 62f74df0c31e8b7f0b92b47827c180ee58bb11747ada526c0401944a1ef9d8ea
sha512: 71f94069011f8456db014ae6d41360fe8ad2718ca74c66df6b61c4ea738d2e137a4d672c63962e4ca18b4327a125886d07772d66aaff716aaa7c5689eb59c7c7
ssdeep: 6144:rVlWOtreUekfps+jF46iGqf3EEJEnKQ3edyBiqiDZOa2xov:rVZrACFRiGq/rez3edTz2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C244028F96E4C1B1C9D142F456B2F1CAD47351158B308657F3C2C889B97EAB5AE304FA
sha3_384: a26c93fbb9b9584434a1e69e486f4604f710bd7f574c23d68b4eaa2763d69918e20e94af0f58996c9a3bd5492b0d44d4
ep_bytes: 68a400000068000000006828af4000e8
timestamp: 2012-12-18 17:33:38

Version Info:

0: [No Data]

Mal/Generic-R + Mal/ZboCheMan-L also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Encpk.Gen.1
FireEyeGeneric.mg.f02f45eac24b4cef
CAT-QuickHealVirTool.CeeInject.A
ALYacTrojan.Encpk.Gen.1
CylanceUnsafe
VIPRETrojan.Win32.Encpk.afnb (v)
K7AntiVirusTrojan ( 0040f2521 )
AlibabaVirTool:Win32/Injector.9b6bdb3b
K7GWTrojan ( 0040f2521 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.AXNY
CyrenW32/Buzus.X.gen!Eldorado
SymantecPacked.Generic.415
ESET-NOD32a variant of Win32/Injector.AAKJ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ransom-58
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Encpk.Gen.1
NANO-AntivirusTrojan.Win32.Panda.feudxk
AvastWin32:Crypt-OPU [Trj]
TencentMalware.Win32.Gencirc.10b9a89c
Ad-AwareTrojan.Encpk.Gen.1
EmsisoftTrojan.Encpk.Gen.1 (B)
ComodoTrojWare.Win32.Injector.AAJW@4swo9i
DrWebTrojan.PWS.Panda.655
ZillyaTrojan.Zbot.Win32.91848
TrendMicroTROJ_SPNR.35AA13
McAfee-GW-EditionBehavesLike.Win32.ZBot.dc
SophosMal/Generic-R + Mal/ZboCheMan-L
SentinelOneStatic AI – Malicious PE
GDataTrojan.Encpk.Gen.1
JiangminTrojanSpy.Zbot.colz
WebrootW32.Rogue.Gen
AviraTR/Spy.Zbot.ajoumea
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Zbot.hm.(kcloud)
ArcabitTrojan.Encpk.Gen.1
ViRobotTrojan.Win32.A.Zbot.183808.DO
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/CeeInject.gen!ID
AhnLab-V3Trojan/Win32.Zbot.R49007
Acronissuspicious
McAfeePWS-Zbot.gen.anm
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.622438215
TrendMicro-HouseCallTROJ_SPNR.35AA13
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.Injector!GG24j+r2Xd0
IkarusVirus.Win32.CeeInject
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.ANM!tr
BitDefenderThetaGen:NN.ZexaF.34212.quW@aqwBTsjO
AVGWin32:Crypt-OPU [Trj]
Cybereasonmalicious.ac24b4
PandaTrj/Ransom.AB

How to remove Mal/Generic-R + Mal/ZboCheMan-L?

Mal/Generic-R + Mal/ZboCheMan-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment