Categories: Malware

What is “Mal/Generic-R + Troj/Agent-AYLK”?

The Mal/Generic-R + Troj/Agent-AYLK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Agent-AYLK virus can do?

  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Troj/Agent-AYLK?


File Info:

crc32: 0E2D5470md5: 513416d9443b24bdc49e7fb922be2d21name: 513416D9443B24BDC49E7FB922BE2D21.mlwsha1: 9cb94d7a7d66c86580ef38e767671dac7ad23b62sha256: 9c36ad62419e7df3d33449967eddfbad874b5a5c83c516d4a4f616353be42febsha512: 1221906d1693fd6c688e5148f6f347755fe4d7fe98eaf118d6e6cc27566cba776767fa57b82f20268d55d57d375df52ca5653a7fba10cace0fb8985005b08224ssdeep: 24576:40aWgWHZscZqsBA9tDm2azuavCH9lBsSuk2DxbByXdYfL0:4JMFZiIKlySukXatype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2016 NVIDIA Corporation. All rights reserved.FileVersion: 1.2.0.0CompanyName: NVIDIAProductName: NVIDIA ContainerProgramID: NVIDIA ContainerProductVersion: 1.2.0.0FileDescription: NVIDIA ContainerOriginalFilename: NvContainer.exeTranslation: 0x0409 0x04e4

Mal/Generic-R + Troj/Agent-AYLK also known as:

Bkav W32.ClipBankerDFC.Trojan
K7AntiVirus Trojan ( 00523f661 )
Elastic malicious (high confidence)
DrWeb Trojan.ClipSpy.27
ALYac Gen:Heur.Mint.SP.Sneaky.1
Cylance Unsafe
Zillya Trojan.Agent.Win32.880232
K7GW Trojan ( 00523f661 )
Cybereason malicious.9443b2
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/ClipBanker.CF
APEX Malicious
Avast Win32:Malware-gen
Kaspersky Trojan-Banker.Win32.Agent.aeio
BitDefender Gen:Heur.Mint.SP.Sneaky.1
NANO-Antivirus Trojan.Win32.ClipBanker.eyjwbf
MicroWorld-eScan Gen:Heur.Mint.SP.Sneaky.1
Tencent Malware.Win32.Gencirc.114ce1ef
Ad-Aware Gen:Heur.Mint.SP.Sneaky.1
Sophos Mal/Generic-R + Troj/Agent-AYLK
BitDefenderTheta Gen:NN.ZelphiF.34688.QP0@aCcLIhji
VIPRE Trojan.Win32.Generic!BT
TrendMicro TROJ_BTCCLIP.SMMR
McAfee-GW-Edition BehavesLike.Win32.Infected.th
FireEye Generic.mg.513416d9443b24bd
Emsisoft Gen:Heur.Mint.SP.Sneaky.1 (B)
Jiangmin Trojan.Banker.Agent.agc
Webroot W32.Trojan.Gen
Avira TR/ClipBanker.cbaoi
Antiy-AVL Trojan/Generic.ASMalwS.244F5E9
Microsoft Trojan:Win32/CryptoJacker.A
Arcabit Trojan.Mint.SP.Sneaky.1
AegisLab Trojan.Win32.Agent.7!c
GData Gen:Heur.Mint.SP.Sneaky.1
AhnLab-V3 Trojan/Win32.Banker.R222073
McAfee GenericRXDW-LQ!513416D9443B
MAX malware (ai score=98)
VBA32 TScope.Trojan.Delf
Malwarebytes Malware.AI.4289119539
Panda Trj/GdSda.A
TrendMicro-HouseCall TROJ_BTCCLIP.SMMR
Rising Trojan.ClipBanker!8.5FB (C64:YzY0OqmMMwlgBaSe)
Yandex Trojan.GenAsa!MMqWW1d/ktI
Ikarus Trojan.Win32.Clipbanker
Fortinet W32/Generic.AC.403b7c!tr
AVG Win32:Malware-gen
Paloalto generic.ml

How to remove Mal/Generic-R + Troj/Agent-AYLK?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Adware.BrowseFox.305 removal

The Adware.BrowseFox.305 is considered dangerous by lots of security experts. When this infection is active,…

59 mins ago

Win32/AutoRun.VB.AUW (file analysis)

The Win32/AutoRun.VB.AUW is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan:Win64/Metasploit!pz removal guide

The Trojan:Win64/Metasploit!pz is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

What is “Win32/Agent_AGen.BLW”?

The Win32/Agent_AGen.BLW is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Backdoor:MSIL/WebShell.GMF!MTB removal instruction

The Backdoor:MSIL/WebShell.GMF!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Mikey.163204 removal instruction

The Mikey.163204 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago