Malware

Should I remove “Mal/Generic-R + Troj/Agent-BFYB”?

Malware Removal

The Mal/Generic-R + Troj/Agent-BFYB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-BFYB virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

sunray1975.zapto.org

How to determine Mal/Generic-R + Troj/Agent-BFYB?


File Info:

crc32: D6B24351
md5: b7affee7731672577c6bdfaa19860fdd
name: B7AFFEE7731672577C6BDFAA19860FDD.mlw
sha1: 9ad3c8b6b30ee9f924189adc66f15cb433047dd3
sha256: 682d65b9cbe5a63c84647ad8fc13a73d5c4763878e21c5b62b879e89bd92cdf7
sha512: cc812c2d115b1d1d9f3b6821443cb1aa6b4a76cdcf71e7c3c2e4f4af3ca8c1815e24596597c36e604b0720d8b00ab16d735c0022233844eb5387837099c6463a
ssdeep: 49152:ovCgbXJLrduEyztsR7OQzQzAmjqamm173f:oKgbdd/yzt67OU7apv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Agent-BFYB also known as:

K7AntiVirusTrojan ( 00548e051 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7779
ClamAVWin.Trojan.Mbrlock-9779766-0
CAT-QuickHealTrojan.WacatacPMF.S16539689
ALYacGen:Variant.Symmi.34741
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 00548e051 )
Cybereasonmalicious.773167
CyrenW32/Injector.OZVT-2500
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AHHO
APEXMalicious
AvastWin32:MBRlock-DV [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Ransom.Win32.Blocker
BitDefenderGen:Variant.Symmi.34741
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
MicroWorld-eScanGen:Variant.Symmi.34741
TencentTrojan.Win32.Blocker.zg
Ad-AwareGen:Variant.Symmi.34741
SophosMal/Generic-R + Troj/Agent-BFYB
ComodoTrojWare.Win32.Injector.HO@82j6jo
F-SecureDropper.DR/Delphi.Gen
BitDefenderThetaAI:Packer.6C5C7DC621
TrendMicroTROJ_GEN.R03BC0DKE21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.b7affee773167257
EmsisoftGen:Variant.Symmi.34741 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.pkq
AviraDR/Delphi.Gen
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Injector.INK!MTB
ArcabitTrojan.Symmi.D87B5
GDataWin32.Trojan.PSE.1UHCZJG
TACHYONTrojan-Dropper/W32.Dapato.2079232
AhnLab-V3Dropper/Win32.Dapato.R83155
Acronissuspicious
MAXmalware (ai score=80)
VBA32Trojan.Downloader
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DKE21
RisingTrojan.Injector!1.DA56 (CLASSIC)
YandexTrojan.Injector!nfedw5apY3U
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.11913.susgen
FortinetW32/Injector.AHHO!tr
AVGWin32:MBRlock-DV [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-R + Troj/Agent-BFYB?

Mal/Generic-R + Troj/Agent-BFYB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment