Malware

Should I remove “Mal/Generic-R + Troj/Luiha-M”?

Malware Removal

The Mal/Generic-R + Troj/Luiha-M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Luiha-M virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Luiha-M?


File Info:

name: 78ABE987E85714A6BAC3.mlw
path: /opt/CAPEv2/storage/binaries/8bebb4534aeab51cfea74caa435e777dc864b0a7da2cb2203e8c24ac8ea53aff
crc32: 24C2CF00
md5: 78abe987e85714a6bac366c43407c2cf
sha1: ea9f9a9d5b4aa6703bad204f11df6bcf538b804d
sha256: 8bebb4534aeab51cfea74caa435e777dc864b0a7da2cb2203e8c24ac8ea53aff
sha512: 83913d841d3faa87f961eb9585ce548639d63fcea12565ff1e7c184268023a73c190874e4ed35ab4c04fac40a0f3793b1fdd926a1070136e856722b013dbe749
ssdeep: 1536:BxnhmuHsywOKwrpE4AMqfi6HgUu/lED30URnOWoNzDqrjDmgho:3A+lpRqfcUuNEgGeqrGN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10593F266524D9E4AE245933AC10BF0E70CE55C4F2192A72EC7C679FB7CA0514DBCFA60
sha3_384: 994d209581aa1037883368cb4e501151a7031ad2ec40e12fed4ed173872db1c9902986f076367ce7873ab652775b7c30
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Generic-R + Troj/Luiha-M also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Wabot-9783917-0
FireEyeGeneric.mg.78abe987e85714a6
McAfeeGenericRXAA-AA!78ABE987E857
CylanceUnsafe
ZillyaBackdoor.Wabot.Win32.2319
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKD.60021847
K7GWTrojan ( 00129bd51 )
Cybereasonmalicious.7e8571
BitDefenderThetaAI:Packer.FC0CC1B21D
CyrenW32/Wabot.K.gen!Eldorado
SymantecW32.Wabot
ESET-NOD32a variant of Win32/Delf.NRF
BaiduWin32.Backdoor.Wabot.a
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Wabot.a
AlibabaMalware:Win32/Dorpal.ali1000029
NANO-AntivirusTrojan.Win32.Delf.eqwfrm
ViRobotTrojan.Win32.Z.Wabot.96936.MR
MicroWorld-eScanTrojan.GenericKD.60021847
APEXMalicious
RisingBackdoor.Wabot!8.31C (CLOUD)
SophosMal/Generic-R + Troj/Luiha-M
ComodoBackdoor.Win32.Wabot.A@4knk5y
DrWebTrojan.MulDrop6.64369
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nc
EmsisoftTrojan.GenericKD.60021847 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm.Generic.gbw
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.C66A
MicrosoftBackdoor:Win32/Wabot.A
GDataTrojan.GenericKD.60021847
AhnLab-V3Backdoor/Win32.Wabot.R222262
VBA32Backdoor.Wabot
ALYacTrojan.GenericKD.60021847
TACHYONBackdoor/W32.WaBot.96936.B
MalwarebytesBackdoor.Wabot
PandaTrj/Genetic.gen
TencentTrojan.Win32.Wabot.a
YandexBackdoor.Wabot!sCKKxb6+WV8
IkarusBackdoor.Wabot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.NRF!tr
AVGWin32:Delf-VKB [Trj]
AvastWin32:Delf-VKB [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-R + Troj/Luiha-M?

Mal/Generic-R + Troj/Luiha-M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment