Malware

Should I remove “Generic.LoadaRat.A.23C0A30C”?

Malware Removal

The Generic.LoadaRat.A.23C0A30C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.LoadaRat.A.23C0A30C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Generic.LoadaRat.A.23C0A30C?


File Info:

name: AACCAB4FE3D4B4C66F0B.mlw
path: /opt/CAPEv2/storage/binaries/285a96aa973c3e5aa8851714911fe4c2cf0c8f1c89fea2b8f20aa39d1cd4f8dc
crc32: 9278C9D6
md5: aaccab4fe3d4b4c66f0b3e6deef99305
sha1: d44ceeb84e9e9eda9126af1e6f5d36926d23fe21
sha256: 285a96aa973c3e5aa8851714911fe4c2cf0c8f1c89fea2b8f20aa39d1cd4f8dc
sha512: 5de0e7bc3c6725d19584073b8773ed2f67751b53966160e6f98fd2953a329812d4509efdaffe41028f0581b0b4347d9510853f2bbd18537a46c2f8c4c5a7cbfe
ssdeep: 24576:P4lavt0LkLL9IMixoEgeaTdtje+avxMZS44AkkXzmALUXMq9MmCS:Kkwkn9IMHeaTDe+avxx4KkDLw8aPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD55D01373EEC3A1C3B29133BA56BB01AEBB7C2505A5F09B2FD5093DE960161521E673
sha3_384: 58fee0f05739c19958fc5203058bd95f362a11ffe988b948de5a809107fa4bbe3994d4d45b7b64bdc7c57d2437b52b5a
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2022-05-07 10:51:39

Version Info:

Translation: 0x0809 0x04b0

Generic.LoadaRat.A.23C0A30C also known as:

BkavW32.AIDetect.malware1
ClamAVTxt.Malware.LodaRAT-9769386-0
McAfeeTrojan-AutoIt.g
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.MultiDropper_c.VK
CyrenW32/Agent.AFI.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Autoit.EJ
APEXMalicious
AvastAutoIt:KeyLogger-R [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Script.LodaRat.a
BitDefenderGeneric.LoadaRat.A.23C0A30C
MicroWorld-eScanGeneric.LoadaRat.A.23C0A30C
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
Ad-AwareGeneric.LoadaRat.A.23C0A30C
EmsisoftGeneric.LoadaRat.A.23C0A30C (B)
DrWebWin32.HLLW.Autoruner2.30870
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.aaccab4fe3d4b4c6
SophosGeneric ML PUA (PUA)
GDataGeneric.LoadaRat.A.23C0A30C (2x)
AviraHEUR/AGEN.1245465
ArcabitGeneric.LoadaRat.A.23C0A30C
ZoneAlarmHEUR:Backdoor.Script.LodaRat.a
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ALYacGeneric.LoadaRat.A.23C0A30C
MAXmalware (ai score=81)
VBA32Trojan.Autoit.F
MalwarebytesMachineLearning/Anomalous.100%
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Agent.DB!tr
BitDefenderThetaAI:Packer.1D0DF3E616
AVGAutoIt:KeyLogger-R [Trj]
Cybereasonmalicious.fe3d4b

How to remove Generic.LoadaRat.A.23C0A30C?

Generic.LoadaRat.A.23C0A30C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment