Malware

Mal/Generic-R + Troj/Virtum-Gen information

Malware Removal

The Mal/Generic-R + Troj/Virtum-Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Virtum-Gen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Enumerates services, possibly for anti-virtualization
  • Detects the presence of Wine emulator via function name
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • The sample wrote data to the system hosts file.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

surfacechicago.net
imagehut4.cn

How to determine Mal/Generic-R + Troj/Virtum-Gen?


File Info:

crc32: 86B853B3
md5: 0eed9df8e290a4d78133931866e9e4c6
name: 0EED9DF8E290A4D78133931866E9E4C6.mlw
sha1: 7c5158b7fd26e18f935a8297008672acf2fe7166
sha256: 904708e3a8400f370f2f6178f7c48204a22c9b8c57bc5e2920ccae38b006c9b2
sha512: 3361c7f9a0b98d5d470bd637617fb567942689094328e1ccedcf9e9ddf0c014844fda8bc15e9cc2aeb5ce51c8cd30b58d9644b2eb300e5f1962bcef44ae21948
ssdeep: 6144:eVl7CJ4XRHEwWwTJvQM5xVLgEgjcZ9UHxGt0ZHa1dkyZbfPsnJ4y:eVi8HE3UoM5zLCjcTMa1eyZb3snSy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Lxraypmvj Yrlmrzwosql. All rights reserved.
InternalName: qmgr.dll
FileVersion: 6.2.2600.1106 (xpsp1.020828-1920)
CompanyName: Vpbcjvttb Dpjupmemqsi
ProductName: Tawopptvqxae Szptyovxae Uyokyumyw Zxuxfr
ProductVersion: 6.2.2600.1106
FileDescription: Background Intelligent Transfer Service
OriginalFilename: qmgr.dll
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Virtum-Gen also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
DrWebTrojan.Click1.63849
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Pirminay.Win32.1134
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.8e290a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Ponmocup.GA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-316164
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Click1.ecklpq
ViRobotTrojan.Win32.A.Pirminay.354668[UPX]
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp[Cont]
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Pirminay.Kqf
Ad-AwareTrojan.Ransom.Cerber.1
SophosMal/Generic-R + Troj/Virtum-Gen
ComodoMalware@#1oxoay6se5n0u
BitDefenderThetaGen:NN.ZexaF.34688.vmLfaW6eeSli
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PE621
McAfee-GW-EditionGeneric Malware.ms
FireEyeGeneric.mg.0eed9df8e290a4d7
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Pirminay.afv
WebrootW32.Trojan.Pirminay.Gen
AviraTR/Crypt.XPACK.Gen2
eGambitGeneric.Malware
MicrosoftTrojanDownloader:Win32/Ponmocup.A
AegisLabTrojan.Win32.Pirminay.4!c
GDataTrojan.Ransom.Cerber.1
McAfeeGeneric Malware.ms
MAXmalware (ai score=99)
VBA32BScope.Trojan.Pirminay
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0PE621
RisingTrojan.Ponmocup!8.136 (CLOUD)
YandexTrojan.Kryptik!y7Hm8878nYs
IkarusTrojan.Win32.Pirminay
FortinetW32/Kryptik.ANL!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Mal/Generic-R + Troj/Virtum-Gen?

Mal/Generic-R + Troj/Virtum-Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment