Malware

Mal/Generic-S + Troj/Formbok-LR removal

Malware Removal

The Mal/Generic-S + Troj/Formbok-LR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Formbok-LR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Troj/Formbok-LR?


File Info:

crc32: CBDD5993
md5: 6e4c0f36925920168887f4c5e4fcef3d
name: 6E4C0F36925920168887F4C5E4FCEF3D.mlw
sha1: c01e14fc7d87b1879f713d4784346af372b8e776
sha256: 72ffde4a478702e8c679195127f874bb32bc641d910395e99436e5fd6971da17
sha512: c3af841b5e16148edfcdd4daf89440ca50d88c14e63cc7c56340bcd9ea2779a36f0173a5754e8ef848a5a678174170f9fe7c547568a85ebc4242bb4de78789cb
ssdeep: 3072:DQIURTXJ+MoWIg45lLttC5ScCm0cvbFjGsEdD4Pd54i2oHIRk95uYOok7AV2OLGa:Ds9oWSjMCWZjSUPdi1EF4AV23EN1K4T
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Mal/Generic-S + Troj/Formbok-LR also known as:

K7AntiVirusTrojan ( 0057c9941 )
LionicTrojan.Win32.Remcos.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43117
CynetMalicious (score: 100)
ALYacBackdoor.Remcos.A
CylanceUnsafe
ZillyaTrojan.Formbook.Win32.1719
SangforBackdoor.Win32.Remcos.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Tnega.6239828a
K7GWTrojan ( 0057c9941 )
Cybereasonmalicious.c7d87b
CyrenW32/Trojan.CAFG-5879
SymantecTrojan.Gen.2
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.GenericKD.36924544
MicroWorld-eScanTrojan.GenericKD.36924544
TencentWin32.Backdoor.Remcos.Wqnk
Ad-AwareTrojan.GenericKD.36924544
SophosMal/Generic-S + Troj/Formbok-LR
ComodoMalware@#1oalj3mjbjunb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103EJ21
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.dc
FireEyeGeneric.mg.6e4c0f3692592016
EmsisoftTrojan.GenericKD.36924544 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Swotter.nelxl
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega.BK!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Tracur
GDataTrojan.GenericKD.36924544
AhnLab-V3Malware/Win.Generic.C4478554
McAfeeRDN/Generic.dx
MAXmalware (ai score=80)
VBA32Trojan.Wacatac
MalwarebytesSpyware.FormBook
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103EJ21
RisingTrojan.Injector/NSIS!1.D63B (CLASSIC)
YandexTrojan.Igent.bVTfKZ.30
IkarusTrojan.Win32.Injector
FortinetNSIS/Injector.EPJF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Mal/Generic-S + Troj/Formbok-LR?

Mal/Generic-S + Troj/Formbok-LR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment