Malware

About “Mal/Generic-R + Troj/DwnLdr-MDK” infection

Malware Removal

The Mal/Generic-R + Troj/DwnLdr-MDK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/DwnLdr-MDK virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/DwnLdr-MDK?


File Info:

crc32: 3325660E
md5: 273742769189f5e1f2387ea7165692d7
name: 273742769189F5E1F2387EA7165692D7.mlw
sha1: 2a2d2f57a44176fb33f497c1f7a89475c50cd5f0
sha256: 2a6a39ec7c5092a89b45423dff8ee1819cc09e931e31d21e3cb768de453170d7
sha512: cf540f32877f36c7069bf32a279b71e2e58a56c2d20eb5f9d6e877c8aec3370b17d8fd8b260cd56700c0cde2506b6a666347ec913bf787a93aeb44ef5b96591e
ssdeep: 384:3AQfQNZ3l5M2y4cM0pxth9uaTjOYTcJOG/+IIO6Xf4LMWYasYTWj96tgTg:wQOXM2Mxlsd2IIVXQLMLMTPgTg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/DwnLdr-MDK also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.448218
FireEyeGeneric.mg.273742769189f5e1
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDownloader-BIJ.a
CylanceUnsafe
AegisLabTrojan.Win32.Generic.lk0q
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.448218
K7GWTrojan-Downloader ( 000918cf1 )
K7AntiVirusTrojan-Downloader ( 0040f54b1 )
BitDefenderThetaAI:Packer.54A3CF691F
CyrenW32/A-1a76837c!Eldorado
SymantecTrojan.Dropper
BaiduWin32.Trojan.Inject.bm
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.Rubinurd-67
KasperskyHEUR:Trojan.Win32.Miancha.gen
AlibabaTrojanDropper:Win32/Dapato.80887ea4
NANO-AntivirusTrojan.Win32.Autoruner.bbwavd
ViRobotTrojan.Win32.Agent.32786
TencentTrojan.Win32.Miancha.a
Ad-AwareGen:Variant.Razy.448218
SophosMal/Generic-R + Troj/DwnLdr-MDK
ComodoTrojWare.Win32.Toga.B@6vx8t0
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.27746
ZillyaTrojan.MianchaGen.Win32.1
TrendMicroTROJ_DLOADE.SMJ
McAfee-GW-EditionBehavesLike.Win32.Downloader.nm
EmsisoftGen:Variant.Razy.448218 (B)
SentinelOneStatic AI – Malicious PE – Downloader
JiangminTrojanDownloader.Small.akba
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Rubinurd.b
MicrosoftVirTool:Win32/CeeInject.gen!DU
ArcabitTrojan.Razy.D6D6DA
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmHEUR:Trojan.Win32.Miancha.gen
GDataWin32.Trojan.Agent.ASM
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R885
Acronissuspicious
VBA32SScope.Backdoor.Simbot
MAXmalware (ai score=83)
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDownloader.Agent.PTT
TrendMicro-HouseCallTROJ_DLOADE.SMJ
RisingTrojan.Inejctor!1.A7C6 (CLASSIC)
YandexTrojan.GenAsa!mZGpD9iw6WU
IkarusTrojan-Downloader.SuspectCRC
MaxSecureTrojan.Downloader.Rubinurd.bf
FortinetW32/Agent.8D4B!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.69189f
Paloaltogeneric.ml
Qihoo-360Malware.Radar01.Gen

How to remove Mal/Generic-R + Troj/DwnLdr-MDK?

Mal/Generic-R + Troj/DwnLdr-MDK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment