Malware

Mal/Generic-S + Mal/PWS-JT removal instruction

Malware Removal

The Mal/Generic-S + Mal/PWS-JT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/PWS-JT virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • CAPE detected the MALWARE Win XFiles malware family
  • Binary compilation timestomping detected

How to determine Mal/Generic-S + Mal/PWS-JT?


File Info:

name: 9BF74F2CEA994BD2B735.mlw
path: /opt/CAPEv2/storage/binaries/036a5ec95df91e06f025c04af3e3b3911063e5d6e68910d99db58d333187b6e4
crc32: ABD2F5B6
md5: 9bf74f2cea994bd2b735f1c181845bad
sha1: e7296c92b15d52aaec7d934b6be4293304316a63
sha256: 036a5ec95df91e06f025c04af3e3b3911063e5d6e68910d99db58d333187b6e4
sha512: 50beede42835f87bb4dd2d86f034d88ccc44645c07a169bd7352462b36785392dd5c0f8373e16f4295798b4935c8505fcb9f82ccdd6577c66bde41faf5087929
ssdeep: 49152:Lv476Om/Yyj4wu3VjFGEnyt7zSPVtPcoF4b5HIkvfqwgf:DW1m/Ym4x3VjUOhg8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0D55C1437F82F27D2AED3B291B0409297F0F929B363EB9B6581A7794C13B545C422B7
sha3_384: 497ffd2f1ebe93f3e425a6c3e103e2515d5e05d898db7cf693cf85b8192a8e85aa1d593b8ed7c9ef61163dfa03c12fa0
ep_bytes: ff250020400000000000b71dc1046e3b
timestamp: 2070-01-27 13:04:54

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: gosgo
FileVersion: 1.0.0.0
InternalName: ReadLineS0SAT.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: ReadLineS0SAT.exe
ProductName: sgsf
ProductVersion: 1.0.0.0
Assembly Version: 1.1.1.0

Mal/Generic-S + Mal/PWS-JT also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.74
MicroWorld-eScanTrojan.GenericKD.48244098
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacTrojan.GenericKD.48244098
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/AntiVM.8a78dfae
K7GWSpyware ( 004bf53c1 )
K7AntiVirusSpyware ( 004bf53c1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/AntiVM.A suspicious
Paloaltogeneric.ml
ClamAVWin.Packed.Passwordstealera-6872839-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.48244098
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Hyjv
Ad-AwareTrojan.GenericKD.48244098
EmsisoftTrojan-Spy.Agent (A)
ComodoMalware@#mp6ijrr6kvkm
ZillyaTrojan.AntiVM.Win32.128
SophosMal/Generic-S + Mal/PWS-JT
IkarusTrojan.MSIL.Spy
GDataTrojan.GenericKD.48244098
JiangminTrojan.MSIL.unas
Antiy-AVLTrojan/Generic.ASMalwS.350C7CB
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Win.2827776.I
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R457426
McAfeeGenericRXRG-AX!9BF74F2CEA99
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
APEXMalicious
RisingStealer.Agent!1.B723 (CLASSIC)
YandexTrojan.Agent!r++S3tm+Lw8
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Agent.AES!tr.spy
AVGWin32:Malware-gen
Cybereasonmalicious.cea994
PandaTrj/GdSda.A

How to remove Mal/Generic-S + Mal/PWS-JT?

Mal/Generic-S + Mal/PWS-JT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment