Malware

Mal/Generic-R + Troj/Krypt-QO removal

Malware Removal

The Mal/Generic-R + Troj/Krypt-QO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Krypt-QO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the STOP malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Mal/Generic-R + Troj/Krypt-QO?


File Info:

name: 7A1D2EED966DD885268E.mlw
path: /opt/CAPEv2/storage/binaries/65b4396ff74a9d20b6ba291bfb1bbc81610f2c66e0785a3019a9ce9e615ed0b7
crc32: 1D4B931E
md5: 7a1d2eed966dd885268e5ba85d6bdff4
sha1: 8cea0011637c5767efce7f02928b8d3f0632471f
sha256: 65b4396ff74a9d20b6ba291bfb1bbc81610f2c66e0785a3019a9ce9e615ed0b7
sha512: 2f1be00cc028487f8e5765fadf66e426608a4410c33dd84abf69c98069288ff49fc1315657ab41b5224a1ae416f0eb5dcfa3f1331a687f34a466123deb542c2e
ssdeep: 12288:pxuhF3Gt0ubst1VSwkzBElBX/ItxW2YbK34gBeY8cINaCawXMEYFbls7rgZYHTRG:f0uVbGSVaZT2Qm0zxaxE9PQOTRbJS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13605F101EB90D431F5B752F886B6A268B93E3AA09B3454CB57D11AEE17346E0EC3135F
sha3_384: e2751dd9ed8c9a13563df22efd65f540c38ef7f939576e8840719d4a3eade5e6c99e4f31f4a68314547d75042939e507
ep_bytes: 8bff558bece826d60000e8110000005d
timestamp: 2021-03-08 19:10:18

Version Info:

Translations: 0x0489 0x00aa

Mal/Generic-R + Troj/Krypt-QO also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.52
ClamAVWin.Packed.Pwsx-9965190-0
FireEyeGeneric.mg.7a1d2eed966dd885
McAfeeRDN/Real Protect-LS
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005979391 )
BitDefenderGen:Heur.Mint.Zard.52
K7GWTrojan ( 005979391 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Mint.Zard.52
CyrenW32/Agent.EYW.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HQQH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
RisingBackdoor.Mokes!8.619 (TFE:5:fsHRt897T3P)
Ad-AwareGen:Heur.Mint.Zard.52
EmsisoftGen:Heur.Mint.Zard.52 (B)
DrWebTrojan.DownLoader45.14128
VIPREGen:Heur.Mint.Zard.52
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Krypt-QO
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1253214
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASCommon.2BA
MicrosoftTrojan:Win32/Raccoon.RE!MTB
GDataWin32.Trojan.PSE.10619H8
GoogleDetected
AhnLab-V3Trojan/Win.MalPE.R513007
Acronissuspicious
ALYacGen:Heur.Mint.Zard.52
VBA32Trojan.Sabsik
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLA!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]

How to remove Mal/Generic-R + Troj/Krypt-QO?

Mal/Generic-R + Troj/Krypt-QO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment