Malware

How to remove “Mal/Generic-R + Troj/Agent-BGUD”?

Malware Removal

The Mal/Generic-R + Troj/Agent-BGUD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-BGUD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Creates a slightly modified copy of itself

Related domains:

www.P13ZvYzm7n.com
pastebin.com
edgedl.me.gvt1.com

How to determine Mal/Generic-R + Troj/Agent-BGUD?


File Info:

crc32: 656CBE49
md5: 81755e1fdd49d4ef3692db74f0c7535b
name: 81755E1FDD49D4EF3692DB74F0C7535B.mlw
sha1: ed595ce8df18e8e28d8380b41fc0b89fb6a977c0
sha256: 07647672f3e1286338e46a483aad24fb5e03189539c3741f60489118459e250a
sha512: 69d0a4aeaf35c161f8cb1d801f920cff680b91b614ad695c085c4fffdea4b3bedb05944f5e1179838be043e72e34179b06e2aa4d14883141de3fecdc5816cdb2
ssdeep: 24576:NSSG2hReEoUeW4F/SENehJzN/zGo/jbI4EoUeW4F/Si:nG+sEoUeW4FS7JzdzGmhEoUeW4FSi
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Agent-BGUD also known as:

K7AntiVirusTrojan ( 0056e8c71 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic
ALYacTrojan.GenericKDZ.75694
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.b1c842ce
K7GWTrojan ( 0056e8c71 )
Cybereasonmalicious.fdd49d
CyrenW32/Kryptik.CWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GWT
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderTrojan.GenericKDZ.75694
ViRobotTrojan.Win32.Z.Crypt.989184.Z
MicroWorld-eScanTrojan.GenericKDZ.75694
TencentWin32.Trojan.Generic.Dypx
Ad-AwareTrojan.GenericKDZ.75694
SophosMal/Generic-R + Troj/Agent-BGUD
BitDefenderThetaGen:NN.ZexaF.34170.8iZ@ayGm3To
FireEyeGeneric.mg.81755e1fdd49d4ef
EmsisoftTrojan.GenericKDZ.75694 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cib
eGambitUnsafe.AI_Score_98%
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.31CCF5B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKDZ.75694
AhnLab-V3Malware/Win32.Generic.R373212
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=89)
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0RJ121
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Agent!YLT+He18rRs
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.FFP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Mal/Generic-R + Troj/Agent-BGUD?

Mal/Generic-R + Troj/Agent-BGUD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment