Malware

Mal/Generic-R + Troj/Formbo-HV removal guide

Malware Removal

The Mal/Generic-R + Troj/Formbo-HV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Formbo-HV virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Mal/Generic-R + Troj/Formbo-HV?


File Info:

name: F8002F93A79A18028CD4.mlw
path: /opt/CAPEv2/storage/binaries/636d76901b80c7658b291990dd136c3c2790ca3224f8a51babe9b15c10a6f918
crc32: D7554524
md5: f8002f93a79a18028cd45b528fe7ca40
sha1: 7f9ba77c2e3fca9d89577e745ee3e4fbd093967c
sha256: 636d76901b80c7658b291990dd136c3c2790ca3224f8a51babe9b15c10a6f918
sha512: d5f7a40db2ae8c943970e2f2b9e2f0b7c4106b78a6177857f3efb1090f0e3b0e418d7750b9058f04ae7918bf3d7532a8ed28e1da8642445e11075f737f44af94
ssdeep: 6144:WxkifWPWNOpbtor05n1wF4eHjaKzBUj88KPmaDsjVjnLswhZMHAVmltlHwbDLTCJ:WK0Ww4Fx1/eDawcuD60ly0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBA4C01E561AF402C71E2F34E6A1EBFE12F02754DC17921675B83B9ED36A3BA0925313
sha3_384: 2be7f2eaacd80c9e2b386c415573bb8343d9af0a4673d0c35f7883ad4e6684e3d30b42a7ebe95e9c264bd9bc08d9533d
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-08-10 21:05:53

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Formbo-HV also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f8002f93a79a1802
McAfeeFareit-FYD!F8002F93A79A
CylanceUnsafe
ZillyaTrojan.SmartAssembly.Win32.1324
K7AntiVirusTrojan ( 0056c33f1 )
AlibabaTrojanPSW:MSIL/Agensla.21547837
K7GWTrojan ( 0056c33f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Kryptik.BPR.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.XXF
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.43639807
NANO-AntivirusTrojan.Win32.Agensla.hrnwwx
MicroWorld-eScanTrojan.GenericKD.43639807
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan-qqpass.Qqrob.Ebga
Ad-AwareTrojan.GenericKD.43639807
EmsisoftTrojan.GenericKD.43639807 (B)
DrWebTrojan.PackedNET.276
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R022C0PIQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-R + Troj/Formbo-HV
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.43639807
WebrootW32.Trojan.Gen
AviraTR/Redcap.pywfh
Antiy-AVLTrojan/Generic.ASMalwS.30D5DA5
MicrosoftTrojanSpy:Win32/Swotter.A!rfn
AhnLab-V3Trojan/Win32.JobCrypter.R347695
BitDefenderThetaGen:NN.ZemsilF.34294.Cm0@aG4w8yh
ALYacTrojan.GenericKD.43639807
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R022C0PIQ21
YandexTrojan.Igent.bUfp4f.2
IkarusTrojan.MSIL.Crypt
FortinetMSIL/CoinMiner.AY!tr.ransom
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.3a79a1
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.74499699.susgen

How to remove Mal/Generic-R + Troj/Formbo-HV?

Mal/Generic-R + Troj/Formbo-HV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment