Malware

Mal/Generic-R + Troj/Inject-GRQ removal guide

Malware Removal

The Mal/Generic-R + Troj/Inject-GRQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Inject-GRQ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn.discordapp.com
goddywin.freedynamicdns.net

How to determine Mal/Generic-R + Troj/Inject-GRQ?


File Info:

crc32: 696FB576
md5: a78aa7b6d43aa488a112a5967a2d9e94
name: A78AA7B6D43AA488A112A5967A2D9E94.mlw
sha1: c3cbaaf8dac94f932dedc8152da88528d1804c50
sha256: 6889e08e2ea3d797b36013f6e7c75251f488d04f8c79735c396de5dc45e980a2
sha512: 2d0d564751a3a02eee15968fb6106295e027146642f8bb4f29f74dd3adaceadff0549388ae5e67cd8adf91a28bc8661abccba26c9f4466f65e571c8668744ff1
ssdeep: 24576:HWAKGNuegX8P4xLM4npWSdSsiB+kTJhtFvDgIFgq52n:HWAKGKHNc9htFvDpFgqw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Inject-GRQ also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.MulDrop16.9969
MicroWorld-eScanTrojan.GenericKD.36257381
FireEyeGeneric.mg.a78aa7b6d43aa488
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.36257381
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 00576e5b1 )
BitDefenderTrojan.GenericKD.36257381
K7GWTrojan-Downloader ( 00576e5b1 )
CyrenW32/Trojan.VFHK-6841
SymantecTrojan.Gen.2
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Remcos-9827375-1
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/DelfInject.cc84c157
NANO-AntivirusTrojan.Win32.Androm.iiswag
ViRobotTrojan.Win32.Z.Agent.1181424.A
TencentWin32.Trojan.Falsesign.Lneg
Ad-AwareTrojan.GenericKD.36257381
SophosMal/Generic-R + Troj/Inject-GRQ
F-SecureTrojan.TR/Dldr.Delf.fdxmn
TrendMicroBackdoor.Win32.FCVN.USMANAT21
McAfee-GW-EditionPWS-FCVN!A78AA7B6D43A
EmsisoftTrojan.GenericKD.36257381 (B)
IkarusTrojan.MSIL.Inject
JiangminBackdoor.Androm.azdk
AviraTR/Dldr.Delf.fdxmn
Antiy-AVLTrojan[Downloader]/Win32.Delf
MicrosoftTrojan:Win32/DelfInject.SS!MTB
ArcabitTrojan.Generic.D2293E65
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataTrojan.GenericKD.36257381
CynetMalicious (score: 85)
AhnLab-V3Malware/Gen.RL_Reputation.R364528
McAfeePWS-FCVN!A78AA7B6D43A
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.SMY.Generic
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DDP
TrendMicro-HouseCallBackdoor.Win32.FCVN.USMANAT21
RisingDownloader.Delf!8.16F (TFE:4:4O5pXrY7Y7B)
YandexTrojan.Igent.bVe0Lv.97
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/GenKryptik.DPIE!tr
WebrootW32.Malware.Gen
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/TrojanDownloader.DelfInject.HgIASOAA

How to remove Mal/Generic-R + Troj/Inject-GRQ?

Mal/Generic-R + Troj/Inject-GRQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment