Malware

Mal/Generic-R + Troj/AutoIt-CZS malicious file

Malware Removal

The Mal/Generic-R + Troj/AutoIt-CZS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/AutoIt-CZS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Mal/Generic-R + Troj/AutoIt-CZS?


File Info:

name: 1D1902448A4C606C0579.mlw
path: /opt/CAPEv2/storage/binaries/987b2d46466fb788076f0f10668999f2291bd71b84d5b5fb91b043ab73b67d0f
crc32: 19F630FE
md5: 1d1902448a4c606c0579242e9d9c8a90
sha1: 65292d53f6f8e4fb9bc899b562e18cfa02c995ea
sha256: 987b2d46466fb788076f0f10668999f2291bd71b84d5b5fb91b043ab73b67d0f
sha512: 8ff69d1ca1c73f7f378220d6083ddf3170a97e8d4888c4544d4c244346a6a5c7c3e445c003a7bda1ae5f37031d9ef44a2ff6c156d5ec6982d7f6ba9bd5e639a6
ssdeep: 24576:SAHnh+eWsN3skA4RV1Hom2KXSmdaIScFIvnEhoXMWk+fZV4uQoCVxOKHrkGNvab9:Vh+ZkldoPKi2aIni/LzZV+VOwwayZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C75C00273A1C827FE9EB1734B55B251667CEC15012385EF12BA2F79AB701B11A3D36B
sha3_384: f169f47d356992ab4731aee9f09e2009c35a32fbaa7a3f0f663e13bd05c8804ffc97b5aa1860b95327f7a42d830d7259
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2020-03-23 20:55:07

Version Info:

Translation: 0x0809 0x04b0

Mal/Generic-R + Troj/AutoIt-CZS also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Script.Generic.4!c
AVGScript:SNH-gen [Trj]
MicroWorld-eScanTrojan.GenericKD.33560835
CAT-QuickHealTrojan.AutoIt.Skeeyah.C
McAfeeArtemis!1D1902448A4C
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/autoit.ali2000008
K7GWTrojan ( 700000111 )
Cybereasonmalicious.48a4c6
VirITTrojan.Win32.AutoIt.DSS
CyrenW32/AutoIt.KF.gen!Eldorado
SymantecPacked.Generic.548
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Autorun.Spy.Agent.DF
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.33560835
NANO-AntivirusTrojan.Win32.Autorun.hgqrqh
AvastScript:SNH-gen [Trj]
RisingTrojan.Obfus/Autoit!1.C045 (KTSE)
Ad-AwareTrojan.GenericKD.33560835
EmsisoftTrojan.GenericKD.33560835 (B)
ComodoMalware@#36pb6sinl83oh
DrWebTrojan.PWS.Siggen2.45487
VIPRETrojan.GenericKD.33560835
TrendMicroBackdoor.Win32.ANDROM.WLDC
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.1d1902448a4c606c
SophosMal/Generic-R + Troj/AutoIt-CZS
IkarusTrojan.Autoit
GDataWin32.Packed.Kryptik.XZZAIV
WebrootW32.Trojan.GenKD
AviraTR/Agent.ifuhuf
Antiy-AVLTrojan/Generic.ASCommon.1B8
ArcabitTrojan.Generic.D2001903
MicrosoftTrojan:Win32/Predator.AR!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_AutoInj.R272810
ALYacTrojan.GenericKD.33560835
MAXmalware (ai score=85)
VBA32Trojan.Autoit.F
MalwarebytesSpyware.AgentTesla
TrendMicro-HouseCallBackdoor.Win32.ANDROM.WLDC
TencentWin32.Trojan.Generic.Ikjl
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ESJ!tr
PandaTrj/WLT.F
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-R + Troj/AutoIt-CZS?

Mal/Generic-R + Troj/AutoIt-CZS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment