Malware

Mal/Generic-R + Troj/Krypt-K information

Malware Removal

The Mal/Generic-R + Troj/Krypt-K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Krypt-K virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com

How to determine Mal/Generic-R + Troj/Krypt-K?


File Info:

crc32: FCFCECE0
md5: 283cd7c1de6f4f05ab545de5b709b680
name: 283CD7C1DE6F4F05AB545DE5B709B680.mlw
sha1: c786af5d4452b438d0b34722c025f8bf0509df4b
sha256: f008c90d89557c6fc77c36be56ebabf294e414e04ac1ddf00b4fdaa22af3a7f1
sha512: a44d1783fac1f247a67fa964614768a0f7a52d1d095994bbf34fbfe5443e2f0d0f37b5c598524a05f4c753edc6170f92db669085c22461090289b4a46df8d07b
ssdeep: 12288:8z4ljVwWxWjj3fZItPbTJ+nQKv5ZZIS+/hNxaXPMynL:8z4lBtWjjw/J+nQ+57ISghkMynL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: voygmuaroke.exe
FileVersion: 41.29.120.69
Copyright: Copyrighz (C) 2020, wodkaguds
ProductVersion: 14.31.97.13
Translation: 0x0589 0x0119

Mal/Generic-R + Troj/Krypt-K also known as:

K7AntiVirusTrojan ( 005690671 )
LionicTrojan.Win32.Sdum.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43325
ALYacTrojan.GenericKD.37272722
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanPSW:Win32/Glupteba.3916aa3d
K7GWTrojan ( 005690671 )
CyrenW32/Kryptik.EMQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLUF
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKD.37272722
MicroWorld-eScanTrojan.GenericKD.37272722
TencentWin32.Trojan-qqpass.Qqrob.Hqca
Ad-AwareTrojan.GenericKD.37272722
ComodoMalware@#1tfgmjf26ujtp
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.283cd7c1de6f4f05
SophosMal/Generic-R + Troj/Krypt-K
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.hembg
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftRansom.Win32.STOP.ko!se38611
ArcabitTrojan.Generic.D238BC92
ZoneAlarmHEUR:Trojan-PSW.Win32.Racealer.gen
AhnLab-V3CoinMiner/Win.Glupteba.R433005
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CGL21
RisingTrojan.Generic@ML.94 (RDMK:ql003QxPxqN0khi1HbLJgw)
IkarusTrojan-Downloader.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Raccoon.HwoCvq8A

How to remove Mal/Generic-R + Troj/Krypt-K?

Mal/Generic-R + Troj/Krypt-K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment