Malware

Mal/Generic-R + W32/Scribble-B information

Malware Removal

The Mal/Generic-R + W32/Scribble-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + W32/Scribble-B virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

ilo.brenz.pl
duudou.com
anbyin.com
kvmzax.com
hiloyl.com
rrhutj.com
udiyws.com
zarapl.com
vnvfcf.com
yclayk.com
zpbysy.com
ozngur.com
qofeda.com
eqcsjq.com
vsvecu.com
nnibyx.com
neetlh.com
rkueam.com
hayqsq.com
fsrybr.com
omcuna.com
ocuzgp.com
zzatzz.com
fjtmdp.com
wizkbb.com
uxnnbh.com
fajtoi.com
lavipo.com

How to determine Mal/Generic-R + W32/Scribble-B?


File Info:

crc32: 928E3F7B
md5: 12a328ce6651249030f5370f255ca63e
name: 12A328CE6651249030F5370F255CA63E.mlw
sha1: a8048a259c2aeb4bee82eea524e402add040aa35
sha256: 398575a09f41e8b1da28164960e72cdacb331e24922c999e1b9d1887a6ec5a72
sha512: ae03500bd52eff224135ffa4ac5030b6d24538b07e8a01db0cd2ffa5a3ba5202c4eb61fd53722886610299d0994895d6fce7538bf6735f4b348d9c47ef0668b0
ssdeep: 24576:z9WQitvyUilzOUxaOWk01G4fbu/F41jen6KXYzkEEknJS7DFN4L3GmPA705sCvs:z9WDAUozOUxaOyGau6I6WPDvlAAoefk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-R + W32/Scribble-B also known as:

BkavW32.Vetor.PE
K7AntiVirusTrojan ( 005451b81 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.94
CynetMalicious (score: 100)
CAT-QuickHealW32.Virut.G
ALYacTrojan.Ransom.AIG
CylanceUnsafe
SangforRansom.Win32.Sorikrypt.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005451b81 )
Cybereasonmalicious.e66512
BaiduWin32.Virus.Virut.gen
CyrenW32/Sality.D.gen!Eldorado
SymantecW32.Virut.CF
ESET-NOD32Win32/Virut.NBP
ZonerTrojan.Win32.73585
APEXMalicious
AvastWin32:Vitro [Inf]
ClamAVWin.Trojan.CryptoTorLocker2015-1
KasperskyTrojan-Ransom.Win32.Xorist.lk
BitDefenderTrojan.Ransom.AIG
NANO-AntivirusTrojan.Win32.Xorist.dxuuhl
ViRobotWin32.Virut.Gen.C
MicroWorld-eScanTrojan.Ransom.AIG
TencentTrojan.Win32.CryptoTorLocker2015.a
Ad-AwareTrojan.Ransom.AIG
SophosMal/Generic-R + W32/Scribble-B
ComodoVirus.Win32.Virut.CE@5jedjj
BitDefenderThetaAI:FileInfector.C9457D4313
VIPREVirus.Win32.Virut.ce (v)
TrendMicroPE_VIRUX.S-3
McAfee-GW-EditionW32/Virut.af.gen
FireEyeGeneric.mg.12a328ce66512490
EmsisoftTrojan.Ransom.AIG (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bt
WebrootW32.Trojan.Ransom
AviraW32/Virut.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Sorikrypt.A
GDataWin32.Trojan-Ransom.Xorist.D
TACHYONVirus/W32.Virut.Gen
AhnLab-V3Win32/Virut.F
Acronissuspicious
McAfeeW32/Virut.af.gen
MAXmalware (ai score=100)
VBA32Virus.Virut.13
MalwarebytesRansom.FileCryptor
PandaW32/Sality.AO
TrendMicro-HouseCallPE_VIRUX.S-3
RisingVirus.Virut!1.A08B (CLOUD)
IkarusTrojan-Ransom.Xorist
MaxSecureVirus.Virut.CE
FortinetW32/Filecoder.Q!tr.ransom
AVGWin32:Vitro [Inf]
Paloaltogeneric.ml

How to remove Mal/Generic-R + W32/Scribble-B?

Mal/Generic-R + W32/Scribble-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment