Malware

Generic.Bazar.3.A9025A8B removal tips

Malware Removal

The Generic.Bazar.3.A9025A8B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Bazar.3.A9025A8B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Mimics the system’s user agent string for its own requests
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Generic.Bazar.3.A9025A8B?


File Info:

name: 0796F1C1EA0A142FC1EB.mlw
path: /opt/CAPEv2/storage/binaries/3400a7df9ec3dc8283d5ac7accb6935691e93feda066cc46c6c04d67f7f87b2b
crc32: 388EC353
md5: 0796f1c1ea0a142fc1eb7109a44c86cb
sha1: 335743acfd91055a2c98ef0400a3c414464aa004
sha256: 3400a7df9ec3dc8283d5ac7accb6935691e93feda066cc46c6c04d67f7f87b2b
sha512: 70512b01975a393e21f94f99fa17e2c4df13732bd53591d9c9f4a9160a04ba524736684e0c4ab181c9c93c542da4e1d2306968af98d9f645402382c7f96c850c
ssdeep: 768:PfFe0W7ohwU17d2yro3+1bex7KcDhIlOlftsuiJ7G7Nm3SvXpXe4q:Pt47oSq7dT71beBKIYKVsuRNX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0237C42BE95F832CA2201F2693AE996DA7B65301B4475F7FB40DC482C796D0EC3A317
sha3_384: adc3c5351557012649b49c04ec6c222b889c19035fe1d22f0fdc571197379e636253c4b299fba02600f125d94b85f010
ep_bytes: e8bb040000e97afeffff558bec8b4508
timestamp: 2020-04-07 19:53:53

Version Info:

0: [No Data]

Generic.Bazar.3.A9025A8B also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Bazar.3.A9025A8B
McAfeeTrojan-Trickbot.a
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005653d51 )
AlibabaTrojan:Win32/BazarLoader.8265dfa6
K7GWTrojan ( 005653d51 )
Cybereasonmalicious.1ea0a1
CyrenW32/Trojan.TXBF-3035
ESET-NOD32a variant of Win32/BazarLoader.G
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Winekey-9800040-0
KasperskyTrojan.Win32.Agent.xadram
BitDefenderGeneric.Bazar.3.A9025A8B
NANO-AntivirusTrojan.Win32.Bazar.inquvw
ViRobotTrojan.Win32.S.Agent.45568.SV
AvastWin32:Trojan-gen
RisingBackdoor.Bazar!8.11A5D (CLOUD)
Ad-AwareGeneric.Bazar.3.A9025A8B
EmsisoftGeneric.Bazar.3.A9025A8B (B)
ComodoMalware@#10x73gevnhxq9
DrWebBackDoor.Bazar.4
ZillyaTrojan.Agent.Win32.1327632
TrendMicroTrojan.Win32.BAZARLOADER.YAAJ-A
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
FireEyeGeneric.mg.0796f1c1ea0a142f
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Backdoor.Bazar.A
JiangminTrojan.Agent.cqyr
WebrootW32.Trojan.Gen
AviraTR/Agent.fctic
ArcabitGeneric.Bazar.3.A9025A8B
ZoneAlarmTrojan.Win32.Agent.xadram
MicrosoftTrojan:Win32/Trickbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bazar.C4217106
VBA32BScope.Trojan.Agentb
ALYacTrojan.Mansabo.gen
MAXmalware (ai score=94)
MalwarebytesTrojan.Bazar
TrendMicro-HouseCallTrojan.Win32.BAZARLOADER.YAAJ-A
TencentWin32.Trojan.Agent.Gbu
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.7176781.susgen
FortinetW32/Agent.UEO!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Bazar.3.A9025A8B?

Generic.Bazar.3.A9025A8B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment