Malware

What is “Mal/Generic-R + Troj/Konus-A”?

Malware Removal

The Mal/Generic-R + Troj/Konus-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Konus-A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:32767, 127.0.0.1:32768
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Queries information on disks, possibly for anti-virtualization
  • Sniffs keystrokes

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ipify.org
time-a.nist.gov

How to determine Mal/Generic-R + Troj/Konus-A?


File Info:

crc32: 787349D0
md5: e2f99487e970a27006cf282abab1d49a
name: E2F99487E970A27006CF282ABAB1D49A.mlw
sha1: b5d6b3b95f265888ce74e1be495858928214eb00
sha256: 7176b06d8ef959057db3fa2868695ee2d3e810353fb236923840903ddb47019a
sha512: 40e23b344272daba585c707e7e6298450049102052ae516b7b98ca0591274676cdc4e9891d149204595388b0347ed701b42b65c64901683a17c930f925a19351
ssdeep: 12288:rXPcLcbGfVylwG/ZDCK/ScBXo8TsyMkKMY8m7WOK98YjTTsx/SA/WegYfdNbrqn:rXh6XcBXo8TsL8Y8mWjTTySA/DrfdNb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Konus-A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00539c471 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.36652
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.25
CylanceUnsafe
ZillyaBackdoor.Konus.Win32.70
SangforTrojan.Win32.Save.a
K7GWSpyware ( 00539c471 )
Cybereasonmalicious.7e970a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Kronosbot.A
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Konus.sf
BitDefenderGen:Heur.Mint.Zard.25
NANO-AntivirusTrojan.Win32.Konus.ilrxvn
MicroWorld-eScanGen:Heur.Mint.Zard.25
Ad-AwareGen:Heur.Mint.Zard.25
SophosMal/Generic-R + Troj/Konus-A
BitDefenderThetaAI:Packer.10C3B9AA1E
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.e2f99487e970a270
EmsisoftGen:Heur.Mint.Zard.25 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Konus.ch
AviraHEUR/AGEN.1116604
eGambitUnsafe.AI_Score_98%
MicrosoftBackdoor:Win32/Konus.A
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Mint.Zard.25
GDataWin32.Trojan-Spy.Kronos.W3LYIZ
TACHYONBanker/W32.Osiris.444928
AhnLab-V3Trojan/Win32.RL_Banker.R277924
Acronissuspicious
McAfeeGenericRXNP-XC!E2F99487E970
MAXmalware (ai score=84)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
RisingBackdoor.Kronos!1.D39A (RDMK:cmRtazq6g3XCmBjo1aBOHFt/ERZA)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.114274721.susgen
AVGWin32:Trojan-gen

How to remove Mal/Generic-R + Troj/Konus-A?

Mal/Generic-R + Troj/Konus-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment