Malware

Mal/Generic-R + Troj/Agent-BGBL removal instruction

Malware Removal

The Mal/Generic-R + Troj/Agent-BGBL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-BGBL virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Troj/Agent-BGBL?


File Info:

crc32: A1795206
md5: 8e39267ec46fbd8f99132c02494753ca
name: 8E39267EC46FBD8F99132C02494753CA.mlw
sha1: 3fd07d09c68f593805e8460787e1ae72a19d65ea
sha256: 65bbb3844e24e5c0018dfcd97e5c1001675dfd3d6bc5f2fcec8d1ceb7ce5b18f
sha512: ec2dcc718e1fd1b81b5bb9ce445659b2032eb6a237d9eb658779ad89b8adc106519277dcfff52cc9248f8ada7efc277ea9c18ce3f718f9b0957855b9787b77d9
ssdeep: 1536:nSgy19JSVO1ONn511/twZXRzOmRktzYX5mUqta0jVwtjZpEp:nS7BE51XwZBzOcktzjUhhm
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Agent-BGBL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35191545
FireEyeGeneric.mg.8e39267ec46fbd8f
CAT-QuickHealTrojan.GenericCS.S18137171
Qihoo-360Win32/TrojanDropper.Dinwod.HxMBCNoA
ALYacTrojan.GenericKD.35191545
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005734db1 )
BitDefenderTrojan.GenericKD.35191545
K7GWTrojan ( 005734db1 )
Cybereasonmalicious.ec46fb
BitDefenderThetaGen:NN.ZexaF.34804.eeY@ayxWNuo
CyrenW32/S-dd34b2aa!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.kkrunchy-7049457-1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDropper:Win32/Dinwod.b3487652
NANO-AntivirusTrojan.Win32.GenKryptik.fpevjn
AegisLabTrojan.Win32.Generic.lqi8
TencentMalware.Win32.Gencirc.10ce1d59
Ad-AwareTrojan.GenericKD.35191545
SophosMal/Generic-R + Troj/Agent-BGBL
ComodoTrojWare.Win32.Trojan.Inject.~INC@1f34i5
F-SecureTrojan.TR/Drop.Dinwod.cpdeh
DrWebTrojan.Inject2.4876
ZillyaTrojan.Generic.Win32.1268196
TrendMicroTROJ_GEN.R03BC0DB121
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
EmsisoftTrojan.GenericKD.35191545 (B)
IkarusTrojan-Dropper.Win32.Dinwod
JiangminTrojan.Generic.dfvtj
AviraTR/Drop.Dinwod.cpdeh
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.Bifrose
MicrosoftTrojanDropper:Win32/Dinwod
GridinsoftTrojan.U.Downloader.oa
ArcabitTrojan.Generic.D218FAF9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.84L4KD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dinwod.R271738
Acronissuspicious
McAfeeGenericRXMU-FR!8E39267EC46F
VBA32Trojan.Slowpack
MalwarebytesGeneric.Trojan.Dropper.DDS
ESET-NOD32a variant of Win32/Packed.KKrunchy.S
TrendMicro-HouseCallTROJ_GEN.R03BC0DB121
RisingTrojan.Shyape!1.B5E8 (CLOUD)
YandexTrojan.Agent!pMBBqowQyqQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Krunchy.A!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Mal/Generic-R + Troj/Agent-BGBL?

Mal/Generic-R + Troj/Agent-BGBL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment