Malware

Generic.AutoHotKey.Agent.A.CCC70DB2 (file analysis)

Malware Removal

The Generic.AutoHotKey.Agent.A.CCC70DB2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.AutoHotKey.Agent.A.CCC70DB2 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generic.AutoHotKey.Agent.A.CCC70DB2?


File Info:

name: 4D03FD23DA779B9C31CA.mlw
path: /opt/CAPEv2/storage/binaries/03fbe28b8eceb7aeac1d77469e79f07cfd83b64c1b3d61c3fc01e4d2c10823ed
crc32: 5FB7183D
md5: 4d03fd23da779b9c31ca3a68fa747426
sha1: 54f25e9f18fdccffe0e6eb1b978aa9ede624cfb9
sha256: 03fbe28b8eceb7aeac1d77469e79f07cfd83b64c1b3d61c3fc01e4d2c10823ed
sha512: 18dff02aaf181c167f04aa90480975175d6ff8cccb5b3be04308c2314bdcada9b43b55e9aa049c79492706133adeeee517e63f9f78adc9e2f3d0cceb34016ac4
ssdeep: 12288:VcgANG5elQUYhOIS4N5azvWbHRRkkDoNIJjoerY2XxqGBI:VcgANiXhDSAazebRRkuJjoeVwGBI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177057C53B3C7D0B2DFA625F3D6B49376193AB938173C89CB7390282DE8906C16A35355
sha3_384: a54b33197c847d5b2507be9d1755b13c500cebb96cca342897933fa0d26cce077ddf6bd1d77db1e99139fa0116403ff2
ep_bytes: e8f05b0000e989feffffcccccc568b44
timestamp: 2021-05-08 03:58:23

Version Info:

0: [No Data]

Generic.AutoHotKey.Agent.A.CCC70DB2 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGeneric.AutoHotKey.Agent.A.CCC70DB2
FireEyeGeneric.mg.4d03fd23da779b9c
ALYacGeneric.AutoHotKey.Agent.A.CCC70DB2
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1401034
SangforTrojan.Win32.Packed.Vjh9
K7AntiVirusTrojan ( 005814481 )
AlibabaPacked:Win32/Generic.8fd64712
K7GWTrojan ( 005814481 )
Cybereasonmalicious.f18fdc
CyrenW32/FakeFolder.T.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.AHK.H suspicious
TrendMicro-HouseCallTROJ_GEN.R03BC0PI322
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGeneric.AutoHotKey.Agent.A.CCC70DB2
AvastWin32:Evo-gen [Trj]
Ad-AwareGeneric.AutoHotKey.Agent.A.CCC70DB2
EmsisoftGeneric.AutoHotKey.Agent.A.CCC70DB2 (B)
ComodoApplicUnwnt@#2appf2bhpqjk3
VIPREGeneric.AutoHotKey.Agent.A.CCC70DB2
TrendMicroTROJ_GEN.R03BC0PI322
McAfee-GW-EditionBehavesLike.Win32.Agent.ch
SophosMal/Generic-S
IkarusPUA.AHK
GDataGeneric.AutoHotKey.Agent.A.CCC70DB2
MAXmalware (ai score=87)
ArcabitGeneric.AutoHotKey.Agent.A.CCC70DB2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.C4574886
McAfeeTrojan-FUCG!4D03FD23DA77
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingMalware.FakeFolder/ICON!1.D519 (CLASSIC)
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Trojan
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generic.AutoHotKey.Agent.A.CCC70DB2?

Generic.AutoHotKey.Agent.A.CCC70DB2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment