Malware

Should I remove “Mal/Generic-R + Troj/Agent-ADXT”?

Malware Removal

The Mal/Generic-R + Troj/Agent-ADXT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-ADXT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Collects information to fingerprint the system

How to determine Mal/Generic-R + Troj/Agent-ADXT?


File Info:

name: C7E5EEDAA0AD9A379C50.mlw
path: /opt/CAPEv2/storage/binaries/d464acfac8923918d6fdd456c6cd001af535f45e69f7e2f1b1026dac9e926816
crc32: 6122B1E2
md5: c7e5eedaa0ad9a379c50ca56ffa7bb1b
sha1: ca0f36cea794655b2a82de7d9bcc207a93fff932
sha256: d464acfac8923918d6fdd456c6cd001af535f45e69f7e2f1b1026dac9e926816
sha512: e8f55b32bbc00090cbae0cd196f7817fd4caac97c6f20f0bf3b5aa5fab5f47d7f879d305658ca92c2c1e5d27ffc0340823d436312272bcded761091c76f8a754
ssdeep: 6144:T44b7czK+MOjoF3/di++08qvFsRcfJgohePbrzZ7tfYIKpnzrDgtZ4:84fijVjo1FimlvybohePptgIqV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16564F13C80EC3C5FD8857873559AA19B55614F227AF3D9EBE01831B3CA290E1A73252F
sha3_384: bfa2074b7f74163bc2f2f9e2f5c96a39b79ed0a319222027bdb1572df26a17ce5fdf66c48a7a47728a0aa1d2215c6a2e
ep_bytes: 558bec81ec14020000689c694300ff15
timestamp: 2013-08-23 06:49:47

Version Info:

CompanyName: Корпорация М айкрософт
FileDescription: Диспетчер синхронизации
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
Translation: 0x0419 0x04b0

Mal/Generic-R + Troj/Agent-ADXT also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.GenericKD.48230483
FireEyeGeneric.mg.c7e5eedaa0ad9a37
CAT-QuickHealTrojanDropper.Gepys.A
McAfeePacked-AM!C7E5EEDAA0AD
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040fa341 )
K7GWTrojan ( 0040fa341 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34182.tu3@ayRXRahc
VirITTrojan.Win32.Generic.BHQD
CyrenW32/Zaccess.BC.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.BIRD
TrendMicro-HouseCallTROJ_KRYPTK.SML2
KasperskyTrojan.Win32.ShipUp.ebwd
BitDefenderTrojan.GenericKD.48230483
NANO-AntivirusTrojan.Win32.ShipUp.crnkaf
AvastWin32:Kryptik-MTH [Trj]
TencentMalware.Win32.Gencirc.10b0f04c
TACHYONTrojan/W32.Shipup.326848
EmsisoftTrojan.GenericKD.48230483 (B)
ComodoTrojWare.Win32.Kryptik.BIWI@51iu3y
BaiduWin32.Trojan.Kryptik.ac
VIPRETrojan.Win32.ZAccess.ma (v)
TrendMicroTROJ_KRYPTK.SML2
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-R + Troj/Agent-ADXT
IkarusTrojan.Win32.ShipUp
JiangminTrojan/ShipUp.vl
AviraTR/Kryptik.jduefs
Antiy-AVLTrojan/Generic.ASMalwS.3B62D0
MicrosoftTrojan:Win32/Zbot.SIBL!MTB
GDataTrojan.GenericKD.48230483
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.ZAccess.R80805
VBA32BScope.P2P-Worm.Palevo
ALYacTrojan.GenericKD.48230483
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3268776615
APEXMalicious
RisingDropper.Gepys!8.15D (TFE:dGZlOgKDkLrDq2mUaA)
YandexTrojan.GenAsa!H6ySIOz1nrQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.ShipUp.gen
FortinetW32/Kryptik.HIPQ!tr
AVGWin32:Kryptik-MTH [Trj]
Cybereasonmalicious.aa0ad9
PandaGeneric Malware

How to remove Mal/Generic-R + Troj/Agent-ADXT?

Mal/Generic-R + Troj/Agent-ADXT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment