Worm

Generic.AHKWorm.A.1396C5EF (B) removal tips

Malware Removal

The Generic.AHKWorm.A.1396C5EF (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.AHKWorm.A.1396C5EF (B) virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Generic.AHKWorm.A.1396C5EF (B)?


File Info:

name: A8ABF934036892022593.mlw
path: /opt/CAPEv2/storage/binaries/44c1869aa7b02f2ffba170b14a0971d9eab567710b79a080c12d043b3b0ae385
crc32: 48297772
md5: a8abf9340368920225932e0b457acb5d
sha1: ea94d6cdf8d5bcf9b4c8a1a76d232275dd5560b4
sha256: 44c1869aa7b02f2ffba170b14a0971d9eab567710b79a080c12d043b3b0ae385
sha512: c45c06c10a28aa07eadce12882e59631be74f4f4a7e801430e32eb44dce6e6b79cc8dfa8072ce1a6b616c03d5287da093294e3b5955f0249f298d6fc88371fec
ssdeep: 12288:DTM7W+48qWyfGeGmUU6UjSeUmuJ5PIGww7F5DO3HYNuT:fM7W/8yfTUU6UGZ7lIYF5SXYMT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCE4AE22F68740F7E95120B054BADB725939BA39173A5AD3BBE03D391E201C17A3D35E
sha3_384: c627c80f2ccf67c377d98416e063e6a61e73153a0c8b472aaeef7425209207e52ff607f38d970f295e335cf0731b8bd7
ep_bytes: e8e89c0000e989feffff8bff558bec83
timestamp: 2011-01-18 14:44:33

Version Info:

0: [No Data]

Generic.AHKWorm.A.1396C5EF (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.AHKWorm.A.1396C5EF
FireEyeGeneric.mg.a8abf93403689202
CAT-QuickHealTrojan.Babnock.AZ5
McAfeeArtemis!A8ABF9340368
CylanceUnsafe
VIPREGeneric.AHKWorm.A.1396C5EF
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00468d321 )
K7GWTrojan ( 00468d321 )
Cybereasonmalicious.df8d5b
BitDefenderThetaGen:NN.ZexaF.34698.PqX@amSO1Hn
VirITBackdoor.RBot.TM
SymantecW32.Babonock
ESET-NOD32Win32/AHK.L
BaiduWin32.Trojan.Agent.acd
TrendMicro-HouseCallTROJ_GEN.R03BC0OJ222
ClamAVWin.Malware.Zusy-6804501-0
KasperskyTrojan.Win32.Autoit.amq
BitDefenderGeneric.AHKWorm.A.1396C5EF
NANO-AntivirusTrojan.Win32.TrjGen.brmdeh
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Spybot
APEXMalicious
Ad-AwareGeneric.AHKWorm.A.1396C5EF
EmsisoftGeneric.AHKWorm.A.1396C5EF (B)
ComodoTrojWare.Win32.Spy.Babonock.DQ@6lkp66
DrWebTrojan.MulDrop9.5117
ZillyaTrojan.AutoIT.Win32.7486
TrendMicroTROJ_GEN.R03BC0OJ222
McAfee-GW-EditionBehavesLike.Win32.BadFile.jh
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataWin32.Trojan.PSE1.YWHTA0
JiangminPacked.Katusha.arca
AviraTR/Spy.Babonock.A.7
MAXmalware (ai score=86)
ArcabitGeneric.AHKWorm.A.1396C5EF
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Autoit.C2303692
Acronissuspicious
VBA32Trojan.AHK
ALYacGeneric.AHKWorm.A.1396C5EF
TACHYONTrojan/W32.Agent.680511
MalwarebytesGeneric.Trojan.Malicious.DDS
AvastAutoIt:Agent-DG [Trj]
RisingWorm.Win32.Autorun.uav (CLASSIC)
MaxSecureTrojan.Malware.2051035.susgen
FortinetAutoIt/AHK.L!tr
AVGAutoIt:Agent-DG [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Generic.AHKWorm.A.1396C5EF (B)?

Generic.AHKWorm.A.1396C5EF (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment