Malware

Mal/Generic-R + Troj/AutoIt-DAV removal tips

Malware Removal

The Mal/Generic-R + Troj/AutoIt-DAV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/AutoIt-DAV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to masquerade or mimic a legitimate process or file name

How to determine Mal/Generic-R + Troj/AutoIt-DAV?


File Info:

name: 3C2F70FB4823693349D7.mlw
path: /opt/CAPEv2/storage/binaries/037fe59751ab14b5a2b4067fc804404cbbe5aece4f33bc846b233f739328eca1
crc32: DD087483
md5: 3c2f70fb4823693349d7c687d4b822aa
sha1: 7d6a5284d3eed04c1c9549ccee7b803aa1bbdbae
sha256: 037fe59751ab14b5a2b4067fc804404cbbe5aece4f33bc846b233f739328eca1
sha512: 4986b486e21768a8340902627cf5f7457b661703cdb8b1f6c9aac1e8f3da2f9c0a35d3eb69396d0f003b0735b9c8daac91b5839f4a4dcda7678bed585cc7f454
ssdeep: 6144:EuIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qLqI0ks3ih1XGWG:v6Wq4aaE6KwyF5L0Y2D1PqL43c2v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1647423EA7695E502E86C0372F9670381C5E07931A3B8EB3F70507A0B7CEF0156D9B659
sha3_384: d257578393a524a5b463615c76426dfcb43c48228ecd4ae5f91a1413b16b81abab65f555d33f2a8040d64c74ed94e33a
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Mal/Generic-R + Troj/AutoIt-DAV also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader6.7475
MicroWorld-eScanTrojan.GenericKD.34502385
FireEyeTrojan.GenericKD.34502385
CAT-QuickHealTrojan.AutoIt.Pistolar.A
ALYacTrojan.GenericKD.34502385
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.34502385
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Generic.BGXQ
CyrenW32/AutoIt.RT.gen!Eldorado
SymantecAUT.Heuristic!gen10
ESET-NOD32a variant of Win32/Autoit.OH
TrendMicro-HouseCallTROJ_GEN.R024C0CB322
ClamAVWin.Malware.Autoit-7535251-0
KasperskyTrojan.Win32.Autoit.aza
AlibabaWorm:Win32/Svhoder.fd98ac62
TencentWin32.Trojan.Autoit.Lkeh
SophosMal/Generic-R + Troj/AutoIt-DAV
BaiduAutoIt.Worm.Agent.a
ZillyaTrojan.AutoIT.Win32.14073
TrendMicroTROJ_GEN.R024C0CB322
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.GenericKD.34502385 (B)
JiangminTrojan.MSIL.Zapchast.ag
AviraHEUR/AGEN.1105599
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASCommon.1AE
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Svhoder.A
GDataTrojan.GenericKD.34502385
CynetMalicious (score: 100)
McAfeeArtemis!3C2F70FB4823
VBA32Trojan.Autoit.Wirus
MalwarebytesMalware.AI.1553765799
APEXMalicious
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
IkarusTrojan.Win32.Autoit
eGambitUnsafe.AI_Score_58%
FortinetW32/Sohana.A!tr
AVGAutoIt:Agent-DP [Trj]
Cybereasonmalicious.b48236
AvastAutoIt:Agent-DP [Trj]

How to remove Mal/Generic-R + Troj/AutoIt-DAV?

Mal/Generic-R + Troj/AutoIt-DAV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment