Malware

Mal/Generic-R + Troj/Cryptear-A removal guide

Malware Removal

The Mal/Generic-R + Troj/Cryptear-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Cryptear-A virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
sweet-candy.co.nf

How to determine Mal/Generic-R + Troj/Cryptear-A?


File Info:

crc32: B7A1CD06
md5: a8feb9aed295f9b35b24da83c5122643
name: A8FEB9AED295F9B35B24DA83C5122643.mlw
sha1: 1a3b90f54819332420b2dd18732c93e1f2d34c05
sha256: 4eef696907a31c700e085353c1199579d608de91e76d3eb0ba7a65d758d601af
sha512: 9a9670ab8770b126a0d6a9929de5f1ff9cc55e50a436104ff69c017e0fc7ccbf2eb78db8281063fb1962fab2315c05420ab89b05d5126742699977928953c6e4
ssdeep: 192:4O/spfKLr0b8xNjh2FTC1bfs2hytqhPE1L1tHw9Jeh:r0pf2r0sJh2Fu1bU2hy0hcjtOAh
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: assembly.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: assembly.exe

Mal/Generic-R + Troj/Cryptear-A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGeneric.mg.a8feb9aed295f9b3
Qihoo-360Win32/Ransom.HiddenTear.HgIASOUA
McAfeeRansomware-FTD!A8FEB9AED295
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004de29f1 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 004de29f1 )
Cybereasonmalicious.ed295f
BitDefenderThetaGen:NN.ZemsilF.34590.am1@a0rFySb
SymantecRansom.HiddenTear!g1
ESET-NOD32a variant of MSIL/Filecoder.AK
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/HiddenTear.95d49b9f
NANO-AntivirusTrojan.Win32.Encoder.ezjciu
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
ComodoMalware@#3trw7qcxnobwk
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.10598
ZillyaTrojan.Filecoder.Win32.8349
TrendMicroTrojan.MSIL.EBIWOODZERO.AA.tmsr
McAfee-GW-EditionRansomware-FTD!A8FEB9AED295
SophosMal/Generic-R + Troj/Cryptear-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cbdeq
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/HiddenTear.gen
ArcabitTrojan.Ransom.REntS.Gen.1
AhnLab-V3Trojan/Win32.HiddenTear.C2456715
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan-Ransom.Cryptear.Q
CynetMalicious (score: 100)
VBA32TScope.Trojan.MSIL
ALYacTrojan.Ransom.HiddenTear
MalwarebytesRansom.HiddenTear
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.MSIL.EBIWOODZERO.AA.tmsr
RisingRansom.HiddenTear!8.DC9E (CLOUD)
YandexTrojan.Agent!A7MPEdRE1rQ
IkarusTrojan-Ransom.FileCrypter
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Filecoder.Y!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Generic-R + Troj/Cryptear-A?

Mal/Generic-R + Troj/Cryptear-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment