Malware

Mal/Generic-S + Troj/Formbo-QR removal guide

Malware Removal

The Mal/Generic-S + Troj/Formbo-QR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Formbo-QR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Troj/Formbo-QR?


File Info:

crc32: DF25F81E
md5: 0a13dba66fc4e221cacdde9c759026e0
name: 0A13DBA66FC4E221CACDDE9C759026E0.mlw
sha1: d88a9a0e3da61220006706568192db952b9e3e97
sha256: 04a2b06549eb2ce73a5405a14ba3dd9e13029665382b31984aa41f36841b28d5
sha512: 2c38c6cd8cd0f85dc8fdeaf83be41ef8c8993d43f076347f43da31a55a6fa1f99f807dedeeb65ef551643d60c617ac763cc678584e13551a269f1d31097bf215
ssdeep: 6144:NsA2eVT2GrYBglsTuOOM9xPqSRWtOfZ96xLDXHt:NZXSGsulRuN96x3Xt
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Mal/Generic-S + Troj/Formbo-QR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35898092
FireEyeGeneric.mg.0a13dba66fc4e221
ALYacTrojan.GenericKD.35898092
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005755941 )
BitDefenderTrojan.GenericKD.35898092
K7GWTrojan ( 005755941 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34700.muZ@aK6DJSmi
CyrenW32/Kryptik.CTB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaBackdoor:Win32/Tnega.9570150e
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Wacatac.208896.Y
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Agent!1.D0C5 (CLASSIC)
Ad-AwareTrojan.GenericKD.35898092
SophosMal/Generic-S + Troj/Formbo-QR
ComodoMalware@#1cpo9nbvi90yp
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Stealer.29735
McAfee-GW-EditionBehavesLike.Win32.Packed.dc
EmsisoftTrojan.GenericKD.35898092 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/ATRAPS.Gen
MAXmalware (ai score=81)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega.VAM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D223C2EC
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.35898092
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
VBA32Trojan.Wacatac
MalwarebytesSpyware.TelegramBot.TOR.Generic
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HILO
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.Win32.Crypt
FortinetW32/Malicious_Behavior.VEX
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
Qihoo-360Win32/Backdoor.a07

How to remove Mal/Generic-S + Troj/Formbo-QR?

Mal/Generic-S + Troj/Formbo-QR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment