Malware

How to remove “Mal/Generic-R + Troj/Inject-HAW”?

Malware Removal

The Mal/Generic-R + Troj/Inject-HAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Inject-HAW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Troj/Inject-HAW?


File Info:

crc32: 6E5DBB0B
md5: bcb77b64ef4a369f8b381aff4c6f1c57
name: BCB77B64EF4A369F8B381AFF4C6F1C57.mlw
sha1: 4624958cd8a724ad01868331d9a78a64fb0cdcb0
sha256: 142cf7f01ff7c99da5e16196325e3fa3a6d867ff0e50696d727c92696ba97ccf
sha512: 9249aea1d4a0d467c544271297ee7b88851c586c9afab522f845a071d7551bbefdfc49b516d13bb5d31277ab194026ecd5852e0d751b0527e7543a2d9607405a
ssdeep: 24576:kkirwmPnCRldoDbhC8xyhFOKOl0TWfNBBx6xs30LM:kxrwmPnCS/TxAFOX+TYwxk0LM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Inject-HAW also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.lx9X
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.59710
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37381284
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMAX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.37381284
MicroWorld-eScanTrojan.GenericKD.37381284
TencentWin32.Trojan-spy.Noon.Pjdn
Ad-AwareTrojan.GenericKD.37381284
SophosMal/Generic-R + Troj/Inject-HAW
BitDefenderThetaGen:NN.ZexaF.34058.9qZ@aiIMU6ni
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.bcb77b64ef4a369f
EmsisoftTrojan.GenericKD.37381284 (B)
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Tnega.SM!MTB
GDataTrojan.GenericKD.37381284
AhnLab-V3Malware/Win.Generic.C4587514
McAfeeRDN/Generic.grp
MAXmalware (ai score=84)
VBA32BScope.Trojan-Dropper.Injector
TrendMicro-HouseCallTROJ_GEN.F0D1C00HB21
RisingTrojan.Kryptik!1.D84E (CLASSIC)
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.HMAX!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Noon.HwcBMt8A

How to remove Mal/Generic-R + Troj/Inject-HAW?

Mal/Generic-R + Troj/Inject-HAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment