Malware

About “Mal/Generic-R + Troj/Simbot-J” infection

Malware Removal

The Mal/Generic-R + Troj/Simbot-J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Simbot-J virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.gov.toh.info
www.changeip.com

How to determine Mal/Generic-R + Troj/Simbot-J?


File Info:

crc32: 63A5A040
md5: 87a11a623a1e64eca2ce2d5b58ce2eaf
name: 87A11A623A1E64ECA2CE2D5B58CE2EAF.mlw
sha1: c6b13c42df1d96f6663724fdc6abac6816a86c44
sha256: 23a17b848cc23edb8ff382d541612ee34dbdc54db60573ebb36f57e4b5da8d85
sha512: b40b77590bf46be1e3f3d405dadeacd481fa61d05fc51bc685c07b4174c892b4439939fff3cdef37b0c539e047620fc76302bcf3374d4d4c4776fa3fd8dee1b0
ssdeep: 384:FNtMUszOacWxVMIr//8ISNpIBSGZnG8ma7QkJl2pQy7kQ81lHv:FNtMRb3/9iNpmSQntJlQQwk7F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Simbot-J also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7800
MicroWorld-eScanTrojan.GenericKDZ.74269
CAT-QuickHealBackdoor.Simbot.G4
ALYacTrojan.GenericKDZ.74269
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 001fbdf71 )
K7AntiVirusTrojan ( 001f574c1 )
BaiduWin32.Trojan.Inject.bf
CyrenW32/A-493428c6!Eldorado
ESET-NOD32a variant of Win32/Injector.ELH
APEXMalicious
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Injector-6297684-0
KasperskyTrojan.Win32.Inject.azgw
BitDefenderTrojan.GenericKDZ.74269
NANO-AntivirusTrojan.Win32.Inject.dwskba
ViRobotBackdoor.Win32.Simbot.27136
TencentTrojan.Win32.Inject.bbyoa
Ad-AwareTrojan.GenericKDZ.74269
SophosMal/Generic-R + Troj/Simbot-J
ComodoTrojWare.Win32.Inject.ka@4o81ww
BitDefenderThetaAI:Packer.4CE631F61F
VIPRETrojan.Win32.Inject.cj (v)
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.mh
FireEyeGeneric.mg.87a11a623a1e64ec
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Spy.Zbot.ACM!MTB
ArcabitTrojan.Generic.D1221D
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
GDataTrojan.GenericKDZ.74269
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
McAfeeBackDoor-EYG
MAXmalware (ai score=86)
VBA32SScope.Backdoor.Simbot
MalwarebytesBackdoor.Simbot
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_KRYPTK.SMS
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
FortinetW32/Injector.ELH!tr
AVGWin32:Taidoor-D [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-R + Troj/Simbot-J?

Mal/Generic-R + Troj/Simbot-J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment