Malware

What is “Mal/Generic-S + Mal/Harnig-B”?

Malware Removal

The Mal/Generic-S + Mal/Harnig-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/Harnig-B virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Mal/Generic-S + Mal/Harnig-B?


File Info:

name: 01424B81C4F3A5A19B37.mlw
path: /opt/CAPEv2/storage/binaries/8d8b07bafd3c50f3fad9705a64694991bcb3553b51b8d38dc21df6450c5a2f79
crc32: D85E3EB7
md5: 01424b81c4f3a5a19b377f533bde7303
sha1: 5680358167180a1d5ecbf735d428b8b6be352cb0
sha256: 8d8b07bafd3c50f3fad9705a64694991bcb3553b51b8d38dc21df6450c5a2f79
sha512: 49a6c4d8b0d24ae8f5654ede6c6172aab224099240aab6ee27c2c067a9d1dbefd606597a184d2de7a9c19360b4367d73d7a23193150560d66476dba9f5490595
ssdeep: 768:uSoMcKIvjMl5T7CDbn8eD7+9QfGtj1EwdlrmeHawEv9uOcySWohcKWomU4SoMcK9:IKIwTmshzqwCu9c3KIwTmshh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA43E283DBA45CEEE05BE57E6BE3ED3527D216012787E1D1B30E7243A9474889C0E2C6
sha3_384: 3d9cc361b293e1063d000580244069b8f85a0c53489f31d82e504a676e3c8ee07322cd9ea9b02b83a82290b2f7a731a0
ep_bytes: e93c000000ba3d240000e9610000003b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Mal/Generic-S + Mal/Harnig-B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.01424b81c4f3a5a1
ALYacGen:Variant.Ser.Razy.7042
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Win32/Fikpak.cc1e598e
K7GWTrojan ( 0055485b1 )
K7AntiVirusTrojan ( 0055485b1 )
CyrenW32/S-2dc328d9!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GPTZ
APEXMalicious
KasperskyUDS:Packed.Win32.Fikpak.gen
BitDefenderGen:Variant.Ser.Razy.7042
MicroWorld-eScanGen:Variant.Ser.Razy.7042
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Crypt.Bxi
Ad-AwareGen:Variant.Ser.Razy.7042
EmsisoftGen:Variant.Ser.Razy.7042 (B)
ComodoTrojWare.Win32.Zenshirsh.S@82bjuf
TrendMicroTROJ_HARNIG.SMA
McAfee-GW-EditionBehavesLike.Win32.RAHack.qc
SophosMal/Generic-S + Mal/Harnig-B
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ser.Razy.7042
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
McAfeeGenericRXEK-DL!01424B81C4F3
VBA32Trojan.Occamy
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_HARNIG.SMA
RisingWin32.Virut.cl (CLASSIC)
IkarusTrojan.Win32.Occamy
eGambitUnsafe.AI_Score_59%
FortinetW32/Crypt.E0C9!tr
BitDefenderThetaAI:Packer.C2700E6D1E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.1c4f3a
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Mal/Generic-S + Mal/Harnig-B?

Mal/Generic-S + Mal/Harnig-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment