Malware

How to remove “Mal/Generic-S + Troj/Agent-BHBY”?

Malware Removal

The Mal/Generic-S + Troj/Agent-BHBY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Agent-BHBY virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the RedLineDropperAHK malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

How to determine Mal/Generic-S + Troj/Agent-BHBY?


File Info:

name: B8171D9565A36773AF9C.mlw
path: /opt/CAPEv2/storage/binaries/a78fef83f95d1346a192fe1ed4343c8b23723affd49e48eb38d472f6b0eeeec7
crc32: 5C19589C
md5: b8171d9565a36773af9ced4530f1fc2d
sha1: 1050c2d26c855f051424cb70d2da78cef890a9f9
sha256: a78fef83f95d1346a192fe1ed4343c8b23723affd49e48eb38d472f6b0eeeec7
sha512: 4bed707edb3b7589d2c393d62b82219714d0c914a7d3e59445b804107a9b2e0376756e475bd99bc0ca1aec3a8769875e8951d415e18988e04b74fbc47432fe60
ssdeep: 12288:LgYMCpkm0Odfu2TNJDuRg+W8n8xhio7xUgii2RgNLG:ZpknON1T+BnI1aLi9NK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180C4021034D2C137C5B626764069CBB88EBE756495252ECF9FAA01FC5F18BA1EF1870E
sha3_384: 6f0857b6201d2225a58f9424831c1da2b670b2e152e8412fffa70d7452c7d2ca4efe9134a0fc2ea3aadb78c16c9100f3
ep_bytes: e81d2d0000e979feffff8bff558bec81
timestamp: 2020-09-01 11:51:00

Version Info:

FileVersion: 7.0.2.54
ProductVersion: 7.0.21.21
InternalNames: galimatimot
LegalCopyrighd: Wsekde
Translations: 0x0148 0x1823

Mal/Generic-S + Troj/Agent-BHBY also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.64894
MicroWorld-eScanTrojan.GenericKDZ.74875
FireEyeGeneric.mg.b8171d9565a36773
ALYacTrojan.GenericKDZ.74875
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3118385
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Azorult.763dcbc6
K7GWTrojan ( 0057ba701 )
K7AntiVirusTrojan ( 0057ba701 )
CyrenW32/Kryptik.DZD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKQO
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9856844-0
KasperskyHEUR:Trojan.Win32.Agent.pef
BitDefenderTrojan.GenericKDZ.74875
NANO-AntivirusTrojan.Win32.Stealer.iupwwi
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Kryptik!1.D599 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.74875
SophosMal/Generic-S + Troj/Agent-BHBY
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Crypt
GDataTrojan.GenericKDZ.74875
AviraHEUR/AGEN.1143214
Antiy-AVLTrojan/Generic.ASMalwS.32BB783
MicrosoftTrojan:Win32/Azorult.NV!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Glupteba.R418434
Acronissuspicious
McAfeePacked-GBF!B8171D9565A3
MAXmalware (ai score=87)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
APEXMalicious
YandexTrojan.Kryptik!IhW/6sssCB0
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HKUH!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.26c855
PandaTrj/GdSda.A

How to remove Mal/Generic-S + Troj/Agent-BHBY?

Mal/Generic-S + Troj/Agent-BHBY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment