Malware

Mal/Generic-R + Troj/CeeInj-M malicious file

Malware Removal

The Mal/Generic-R + Troj/CeeInj-M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/CeeInj-M virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
intweb.mobwork.net

How to determine Mal/Generic-R + Troj/CeeInj-M?


File Info:

crc32: 46F3EEC2
md5: ac45f317a444a18abecf2a3ffbcdf083
name: AC45F317A444A18ABECF2A3FFBCDF083.mlw
sha1: deb702db989aba3ad37a01aeecdf26e8f37597ee
sha256: 265657734f432d5c076280fcc025ce361bb366975e301505141dc32e39ba85b6
sha512: ae11004a36c8c6b6b15540cd2a7c580ce015fba4179fc06c74861bde1a3d9e1434baa982f1df018f6f4be196fa999bb9cfca0d7d9be64db8fe0023bf23d2d3cd
ssdeep: 1536:Wnk/oGN6p9asZMSY+A37feaCMJDmYsLIb4PvYqHB/AdGD:W2N6pcsZMSDADeak7dJHB/AdGD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/CeeInj-M also known as:

K7AntiVirusTrojan ( 002331771 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad2.36100
ClamAVWin.Trojan.Inject-132
CAT-QuickHealTrojan.MauvaiseRI.S5243672
ALYacTrojan.GenericKDZ.74269
CylanceUnsafe
ZillyaTrojan.InjectGen.Win32.5
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 001fbdf71 )
Cybereasonmalicious.7a444a
BaiduWin32.Trojan.Inject.bf
CyrenW32/Injector.AV.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Injector.ELH
APEXMalicious
AvastWin32:Taidoor-D [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.bbyo
BitDefenderTrojan.GenericKDZ.74269
NANO-AntivirusTrojan.Win32.Inject.csnmkc
MicroWorld-eScanTrojan.GenericKDZ.74269
TencentTrojan.Win32.Inject.bbyoa
Ad-AwareTrojan.GenericKDZ.74269
SophosMal/Generic-R + Troj/CeeInj-M
ComodoTrojWare.Win32.Inject.ka@4o81ww
BitDefenderThetaAI:Packer.515AA8091F
VIPRETrojan.Win32.Inject.cj (v)
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.kc
FireEyeGeneric.mg.ac45f317a444a18a
EmsisoftTrojan.GenericKDZ.74269 (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Almanahe.C
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.68
MicrosoftTrojan:Win32/Spy.Zbot.ACM!MTB
ArcabitTrojan.Generic.D1221D
SUPERAntiSpywareBackdoor.Bot/Variant
GDataTrojan.GenericKDZ.74269
TACHYONTrojan/W32.Inject.66560.AXAA
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
McAfeeBackDoor-EYG
MAXmalware (ai score=100)
MalwarebytesBackdoor.Simbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMS
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!5YxMY2U2QLk
IkarusBackdoor.Win32.Simbot
MaxSecureTrojan.Inject.bbyo
FortinetW32/Injector.ELH!tr
AVGWin32:Taidoor-D [Trj]

How to remove Mal/Generic-R + Troj/CeeInj-M?

Mal/Generic-R + Troj/CeeInj-M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment