Malware

How to remove “Mal/Generic-S + Mal/Agent-ARA”?

Malware Removal

The Mal/Generic-S + Mal/Agent-ARA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/Agent-ARA virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk

How to determine Mal/Generic-S + Mal/Agent-ARA?


File Info:

name: A23BBFB8F212A6CD21AD.mlw
path: /opt/CAPEv2/storage/binaries/afcb5aa6f3465f0ea72f2cad4469ec4357e31ec6ce24d20cfe939bfe263481d6
crc32: 65483AAE
md5: a23bbfb8f212a6cd21ade700431a1280
sha1: 95d02e3bedde161313cc63061afe62f238e8fe1c
sha256: afcb5aa6f3465f0ea72f2cad4469ec4357e31ec6ce24d20cfe939bfe263481d6
sha512: 6a8364c5b4acdd5b81a979ab377eefab755d776438c5052cf14b7b9d459d2e180d01faa3bef125d747094150ac160e51b18db82ae561b998247d1aae09bd7677
ssdeep: 3072:TqSe5OmiEoAcCbZ6UKGIoutkEnkeBahPmSBPt71:TqzOPI16UKHoSXt4hPhTB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12034E825EAD74DF1E3A785F606F38BB84439B27294631A5FCB988FB13E531314681C98
sha3_384: 0e824ce878364a0939356bc392c80ced488c9748dba5eb7885e6065b943603f33860f8a85744a334fd41634617c50205
ep_bytes: e88b120000e8b311000033c0c3909090
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Mal/Generic-S + Mal/Agent-ARA also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Dinwod.tppB
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.58305
MicroWorld-eScanTrojan.GenericKDZ.72354
FireEyeGeneric.mg.a23bbfb8f212a6cd
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeDropper-FVF!A23BBFB8F212
CylanceUnsafe
ZillyaDropper.DinwodGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000aef511 )
AlibabaMalware:Win32/km_24b5e.None
K7GWTrojan ( 005003ac1 )
Cybereasonmalicious.8f212a
BitDefenderThetaGen:NN.ZexaF.34182.oqZ@aqGriwj
VirITTrojan.Win32.Inject1.DIGN
CyrenW32/BlackMoon.C.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HFLZ
TrendMicro-HouseCallTrojanSpy.Win32.BANKER.SMJC
Paloaltogeneric.ml
ClamAVWin.Trojan.BlackMoon-4255490-1
KasperskyTrojan-Dropper.Win32.Dinwod.acqn
BitDefenderTrojan.GenericKDZ.72354
NANO-AntivirusTrojan.Win32.Dinwod.dnwsrg
AvastWin32:Banker-NBH [Trj]
TencentTrojan.Win32.Dinwod.ya
SophosMal/Generic-S + Mal/Agent-ARA
ComodoPacked.Win32.MUPX.Gen@24tbus
BaiduWin32.Trojan.Agent.acb
VIPRETrojan.Win32.Agent.xfc (v)
TrendMicroTrojanSpy.Win32.BANKER.SMJC
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.GenericKDZ.72354 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Dinwod.pc
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASBOL.C4EC
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftTrojanDropper:Win32/Dinwod
ZoneAlarmTrojan-Dropper.Win32.Dinwod.acqn
GDataWin32.Trojan.PSE.RKU79T
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dinwod.C1708910
VBA32TrojanDropper.Dinwod
ALYacTrojan.GenericKDZ.72354
TACHYONTrojan/W32.GameteaSpy.Zen
MalwarebytesTrojan.Agent
APEXMalicious
RisingBackdoor.Bladabindi!8.B1F (TFE:dGZlOgXLAUFwvj57Sw)
YandexTrojan.DR.Dinwod!yZmMClrOCf8
IkarusTrojan.Win32.Agent
MaxSecureDropper.Dinwod.acqn
FortinetW32/Agent.RGU!tr
AVGWin32:Banker-NBH [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-S + Mal/Agent-ARA?

Mal/Generic-S + Mal/Agent-ARA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment