Malware

Should I remove “Generic.LoadaRat.A.96755E8A”?

Malware Removal

The Generic.LoadaRat.A.96755E8A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.LoadaRat.A.96755E8A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Generic.LoadaRat.A.96755E8A?


File Info:

name: 697A51951CC2F2236978.mlw
path: /opt/CAPEv2/storage/binaries/23deb491792f1a8ff449c5f50c7f5ed9dcf4c2e43f626b5ef1af640068ac849e
crc32: 77B80C38
md5: 697a51951cc2f223697883bcaf92e838
sha1: 9f17175d78877226ff4e38afd1c01a15c9448142
sha256: 23deb491792f1a8ff449c5f50c7f5ed9dcf4c2e43f626b5ef1af640068ac849e
sha512: bcb1ae1a36547760663fda6a067e3ee7854ef2e537d28eed94e55325cb9c53e8e7bca53d405982d2275a1cd4dbafa19d7065613da9e08cc60ba2b868ca83eca6
ssdeep: 24576:0RmJkcoQricOIQxiZY1iaBqSUh5uz9UdnH5qzSYxkfO:RJZoQrbTFZY1iaAScUzmEzSfO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F835E121F5D69036C2F323B19E7EF36A963D69360336D29727C82D315EA05816B29733
sha3_384: f63f21f2e5fa2500041905c8604babffa72f96653404587cafcb0daf08bb4e655cf906447c7901f1131694692245ab81
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Generic.LoadaRat.A.96755E8A also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.697a51951cc2f223
McAfeeTrojan-AutoIt.g
CylanceUnsafe
VIPREGeneric.LoadaRat.A.96755E8A
SangforTrojan.Win32.Save.a
Cybereasonmalicious.51cc2f
CyrenW32/AutoIt.SJ.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Autoit.EJ
APEXMalicious
ClamAVTxt.Malware.LodaRAT-9769386-0
KasperskyHEUR:Backdoor.Script.LodaRat.a
BitDefenderGeneric.LoadaRat.A.96755E8A
MicroWorld-eScanGeneric.LoadaRat.A.96755E8A
AvastAutoIt:KeyLogger-R [Trj]
Ad-AwareGeneric.LoadaRat.A.96755E8A
EmsisoftGeneric.LoadaRat.A.96755E8A (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
GDataGeneric.LoadaRat.A.96755E8A (2x)
AviraHEUR/AGEN.1229437
Antiy-AVLTrojan/Generic.ASBOL.C6D6
ArcabitGeneric.LoadaRat.A.96755E8A
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
ALYacGeneric.LoadaRat.A.96755E8A
MAXmalware (ai score=84)
VBA32Trojan.Autoit.F
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.DB!tr
BitDefenderThetaAI:Packer.1D0DF3E616
AVGAutoIt:KeyLogger-R [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Generic.LoadaRat.A.96755E8A?

Generic.LoadaRat.A.96755E8A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment