Malware

Mal/Generic-R + Troj/VB-HTM removal instruction

Malware Removal

The Mal/Generic-R + Troj/VB-HTM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/VB-HTM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Mal/Generic-R + Troj/VB-HTM?


File Info:

name: B7D528CDB199DCE3662B.mlw
path: /opt/CAPEv2/storage/binaries/6667cd8b9f673595dac2ad9b8bcc2c7ab400cca31c0efd396d4925140e2a533b
crc32: 824574B0
md5: b7d528cdb199dce3662bbc375b257328
sha1: 9512dfb7364f5f2b098537f79a866a110f684a95
sha256: 6667cd8b9f673595dac2ad9b8bcc2c7ab400cca31c0efd396d4925140e2a533b
sha512: 6126f15d9bac2358cafb4876ca3f0543296e8a5972406228352a907130d1a83c92e752bfb3cdb9d8d4a21f00505f05bd0ba5f40dd704bc676041a40ab0de45cd
ssdeep: 3072:tVMKsWKxlGxE07ABigCFHdLYyBvzyBHNGqXgvnHZyzi0zslLFL/FzKsR:T3sWKxQ52CFHdLYKvzyZNGX/Iupj2s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E904436BF121C054E59240B8742CEA8AF55C7E7305446972FB81BB5939B27EFA0F6B03
sha3_384: 1a50ae06a9b6cbdaed1c98fa7786f870b483a3ec87a6354778913e1258ba5eaf4265e3db40c6feb9a4ca2f6a66a40a0f
ep_bytes: 6868784000e8f0ffffff000000000000
timestamp: 2014-03-20 10:41:32

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: DOCUMENT
OriginalFilename: DOCUMENT.exe

Mal/Generic-R + Troj/VB-HTM also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.tnql
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.VB.Agent.ABT
FireEyeGeneric.mg.b7d528cdb199dce3
CAT-QuickHealWorm.Copali.OD3
ALYacBackdoor.VB.Agent.ABT
CylanceUnsafe
ZillyaTrojan.Swisyn.Win32.32299
SangforTrojan.Win32.Agentb.btmh
K7AntiVirusP2PWorm ( 00486ea71 )
BitDefenderBackdoor.VB.Agent.ABT
K7GWP2PWorm ( 00486ea71 )
Cybereasonmalicious.db199d
BitDefenderThetaAI:Packer.B3167EF41F
VirITTrojan.Win32.VB2.ADGJ
CyrenW32/A-0d9bc26b!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.OLE
BaiduWin32.Worm.VB.bf
TrendMicro-HouseCallWORM_COPALI_EJ200083.UVPM
AvastWin32:Agent-AXUS [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.btmh
AlibabaWorm:Win32/Copali.02533a59
NANO-AntivirusTrojan.Win32.TrjGen.deyzgg
ViRobotTrojan.Win32.Zbot.184320.D
RisingWorm.Copali!1.A2C3 (CLOUD)
ComodoTrojWare.Win32.Swisyn.DFX@5ci87q
DrWebTrojan.Siggen6.19362
VIPRETrojan.Win32.Swisyn.dfkc (fs)
TrendMicroWORM_COPALI_EJ200083.UVPM
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
SophosMal/Generic-R + Troj/VB-HTM
APEXMalicious
JiangminTrojan/Swisyn.wsw
WebrootTrojan.Comroki.Gen
AviraTR/Beebone.rhwnabs
Antiy-AVLTrojan/Generic.ASMalwS.93BFFC
MicrosoftWorm:Win32/Copali.B
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
ZoneAlarmTrojan.Win32.Agentb.btmh
GDataBackdoor.VB.Agent.ABT
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.Zbot.R106377
McAfeeW32/Worm-GAM!B7D528CDB199
MAXmalware (ai score=82)
VBA32Trojan.Agentb
MalwarebytesTrojan.Agent
PandaGeneric Malware
TencentMalware.Win32.Gencirc.10b0cd1f
TACHYONTrojan/W32.Agent.184320
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.1EEAF!tr
AVGWin32:Agent-AXUS [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-R + Troj/VB-HTM?

Mal/Generic-R + Troj/VB-HTM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment