Malware

Mal/Generic-S + Troj/Tinba-FN removal

Malware Removal

The Mal/Generic-S + Troj/Tinba-FN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Tinba-FN virus can do?

  • Injection (inter-process)
  • Executable code extraction
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Mimics the system’s user agent string for its own requests
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Xhosa
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Uses suspicious command line tools or Windows utilities

Related domains:

ip-addr.es
myexternalip.com
ocsp.pki.goog
curlmyip.com
crl.pki.goog
crls.pki.goog
spideragroscience.com
conectcon.com
bolle-immobilien.de
myfacecom.com
thecarnivalfest.com
project976.org
xn--e1asbeck.xn--p1ai
basketball256.com
sparshsewa.com
shopshe.com
droidmaza.com
forexinsuracembard.com
abenorbenin.com
naimselmonaj.com
centroinformativoviral.com
doozfriend.com
sudatrain.net
theboomerzblog.com
perpabaskievi.net
noblevisage.com
damozhai.com
suttonfarms.net
rationwalaaa.com
nobilighting.com
reanimator-service.com
fengfeifei.net
grupointernex.com.br
safepeace.com
www.hugedomains.com
ocsp.digicert.com
tmp3malinium.com
virginia-education.com
engagedforpeace.org
ipmon.net
asistent.su

How to determine Mal/Generic-S + Troj/Tinba-FN?


File Info:

crc32: 60655841
md5: b571886dfcaa39fe40a81b29f5bdc9da
name: B571886DFCAA39FE40A81B29F5BDC9DA.mlw
sha1: 147ca78ee51e3965ed41e9ec4ad21ea5a6158e64
sha256: ad8be95773100937fbe2d9b8ceb387a3ca4aeb46d5cd813fe145f72696e31c5e
sha512: c21e1dd4cdfc3a0aab21ed996b302461fd9d27915665a9a340e3b086f56a65674e5645c5f14896c350b0095419c793534ed7493bcd3f43f4b4cc1640266ed05d
ssdeep: 6144:piONmNICShFuRVdd/Al+5ehke/dngNSbKk+o:b1hmdd/Al+5kp5gNT5o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Tillers xa9 2010
ProductName: Strut Shouted
FileDescription: Spadework
FileVersion: 0,174,224,37
CompanyName: SRN Micro Systems

Mal/Generic-S + Troj/Tinba-FN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.514
CynetMalicious (score: 100)
CAT-QuickHealRansome.Teerac.PS4
CylanceUnsafe
ZillyaDropper.Addrop.Win32.694
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dfcaa3
BaiduWin32.Trojan.Kryptik.qb
CyrenW32/Yakes.AR.gen!Eldorado
SymantecRansom.CryptoWall!gm
ESET-NOD32Win32/Filecoder.CryptoWall.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Symmi-1694
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.AD.dymift
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.10b8b0f2
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-S + Troj/Tinba-FN
ComodoMalware@#5v14gr86ur5t
BitDefenderThetaGen:NN.ZexaF.34758.nq1@aOmcrgmG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionRansomCWall-FBJ!B571886DFCAA
FireEyeGeneric.mg.b571886dfcaa39fe
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.buk
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1578950
MicrosoftRansom:Win32/Crowti.A
AegisLabTrojan.Win32.Agent.mCOZ
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeRansomCWall-FBJ!B571886DFCAA
MAXmalware (ai score=84)
VBA32Trojan.Yakes
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingTrojan.Generic@ML.100 (RDML:wdswz90Z+LsREXY0vmnxDg)
YandexTrojan.Filecoder!HSQC3wuXON4
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EEJE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Mal/Generic-S + Troj/Tinba-FN?

Mal/Generic-S + Troj/Tinba-FN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment