Malware

Mal/Generic-S + Mal/EncPk-ZC removal guide

Malware Removal

The Mal/Generic-S + Mal/EncPk-ZC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/EncPk-ZC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Mal/Generic-S + Mal/EncPk-ZC?


File Info:

name: C30DE0FE6D0290AA01BA.mlw
path: /opt/CAPEv2/storage/binaries/fb0a7ad41a8094295ae8fa2941faefef874d50670cda394390a6d0ffdc256088
crc32: 5B4AF5A1
md5: c30de0fe6d0290aa01ba509eee243daa
sha1: 2bf1a120e6033671a053ae0f10cdf10e15b62fd0
sha256: fb0a7ad41a8094295ae8fa2941faefef874d50670cda394390a6d0ffdc256088
sha512: c8e37175441f66ed68c38585bd86ad206911611dc449d8804213b5b7e2be4f87d894cfdbee692a1ca5c9dceaa3eb6afb84b8c95d633d50cfd51ce8bf8193648c
ssdeep: 196608:koGoDFr9U/6/LD8I4rwz9bJMQ6br+6bikW7/H4d4eeNIcUzo:koTDFr9g6X1aEb6bS7/HheLo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147A6330E670FCA6EF6A86571D737A1F0A4C0BE15DF084297E1363DE7BA3E1801C664A5
sha3_384: 1255b7a64b1d76fffefc2a9a05ede254bf377126f5056ee06820d147afc4aa39b412c74042d82891be79e8cfcb906fcd
ep_bytes: 60be0040d1008dbe00d06effc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Mal/Generic-S + Mal/EncPk-ZC also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.c30de0fe6d0290aa
ALYacGen:Variant.Adware.SMSHoax.25
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforTrojan.Win32.Multsarch.Q
AlibabaVirTool:Win32/Obfuscator.ccddcc95
Cybereasonmalicious.e6d029
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Kryptik.MHU
ClamAVWin.Trojan.Agent-1017783
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b4b1f8
Ad-AwareGen:Variant.Adware.SMSHoax.25
SophosMal/Generic-S + Mal/EncPk-ZC
ComodoMalware@#1rl19qc029cft
DrWebTrojan.SMSSend.473
ZillyaTrojan.ArchSMS.Win32.377
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
Ikarusnot-a-virus:Hacktool.SMSHoax
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.bcm
WebrootW32.Adware.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.323628A
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic.Cds.a
MicrosoftVirTool:Win32/Obfuscator
McAfeeGenericRXAA-AA!C30DE0FE6D02
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Kryptik
BitDefenderThetaAI:Packer.BA9DBEF320
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen

How to remove Mal/Generic-S + Mal/EncPk-ZC?

Mal/Generic-S + Mal/EncPk-ZC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment