Categories: Malware

Mal/Generic-R + Troj/Agent-BFBH malicious file

The Mal/Generic-R + Troj/Agent-BFBH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-BFBH virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Anomalous binary characteristics

Related domains:

updt-servc-app2.com

How to determine Mal/Generic-R + Troj/Agent-BFBH?


File Info:

crc32: 0D76EF38md5: ff9a0f3bd4d87ee1eac397836859e4faname: FF9A0F3BD4D87EE1EAC397836859E4FA.mlwsha1: 3db53b56b55b8e69cbfefb260931b62f6b2c42b4sha256: 24e8f4917bb3cf7d6fd91fc1c95e978ea75a0e6da9033911e48b0fda94be62afsha512: d910b24a0331ed5047da8d4ca692cb9aad943bb75ef906c34fe53ea977b6341bdeadee4fa6c07eef021c918e7a4849c3c1304e3d6f21d43762d22cce81d3f5d5ssdeep: 3072:3tchhP3fqvShupTP20Y/MauYgzZPME056BZ7dOln5IzbSF:3UhP3f7uBvT7JddG5IaFtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Microsoft Corporation. All rights reserved.InternalName: rundll32.exeFileVersion: 1.2.0.5CompanyName: MicrosoftProductName: WindowsProductVersion: 6.2.10.0FileDescription: Windows Host ProcessOriginalFilename: rundll32.exeTranslation: 0x0409 0x04b0

Mal/Generic-R + Troj/Agent-BFBH also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 0053c4c91 )
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CAT-QuickHeal Trojan.ApostRI.S10870953
ALYac Trojan.StrongPity.gen
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.13733
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Ransom:Win32/Gandcrab.07b9a74c
K7GW Trojan ( 0053c4c91 )
Cybereason malicious.bd4d87
Cyren W32/Filecoder.V.gen!Eldorado
Symantec Trojan Horse
ESET-NOD32 a variant of Win32/Filecoder.NSD
APEX Malicious
Avast Win32:RansomX-gen [Ransom]
ClamAV Win.Trojan.StrongPity3-8196499-3
Kaspersky HEUR:Trojan.Win32.APosT.vho
BitDefender Trojan.StrongPity.GenericKD.33940429
NANO-Antivirus Trojan.Win32.APosT.incupi
MicroWorld-eScan Trojan.StrongPity.GenericKD.33940429
Tencent Malware.Win32.Gencirc.10b86352
Ad-Aware ATI:StrongPity.Exfil.5D69B91C
Sophos Mal/Generic-R + Troj/Agent-BFBH
Comodo Malware@#1nwp2v0yrehm0
BitDefenderTheta Gen:NN.ZexaF.34738.iy0@a89vKKpi
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.ch
FireEye Generic.mg.ff9a0f3bd4d87ee1
Emsisoft Trojan.StrongPity.GenericKD.33940429 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin Trojan.APosT.aks
Webroot W32.Ransom.Gen
Avira HEUR/AGEN.1117670
Antiy-AVL Trojan/Generic.ASMalwS.30AB1E8
Microsoft Ransom:Win32/Gandcrab
AegisLab Trojan.Win32.APosT.4!c
GData Trojan.StrongPity.GenericKD.33940429
AhnLab-V3 Malware/Win32.Generic.C3655015
McAfee StrongPity!FF9A0F3BD4D8
MAX malware (ai score=80)
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes Trojan.FakeMS
Panda Trj/GdSda.A
Rising Trojan.Generic@ML.100 (RDML:T5FJYbg4Ogh6AG9/Bc4jmg)
Yandex Trojan.Filecoder!BiX15iLfi4I
Ikarus Trojan-Ransom.FileCrypter
Fortinet W32/Filecoder.NSD!tr
AVG Win32:RansomX-gen [Ransom]
Paloalto generic.ml

How to remove Mal/Generic-R + Troj/Agent-BFBH?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Risktool.Flystudio.16024 removal tips

The Risktool.Flystudio.16024 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Trojan.Generic.34363382 removal tips

The Trojan.Generic.34363382 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Should I remove “AIT:Trojan.Nymeria.4438”?

The AIT:Trojan.Nymeria.4438 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

What is “Malware.AI.2428723483”?

The Malware.AI.2428723483 is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

Tedy.551777 (file analysis)

The Tedy.551777 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “Lazy.518842” infection

The Lazy.518842 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago