Malware

How to remove “Mal/Generic-R + Troj/Steal-AUH”?

Malware Removal

The Mal/Generic-R + Troj/Steal-AUH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Steal-AUH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Troj/Steal-AUH?


File Info:

crc32: 41CDCEBB
md5: e9f1e17dbc2b23d3d857b1519f3e8087
name: E9F1E17DBC2B23D3D857B1519F3E8087.mlw
sha1: fc4b66aa17a46cc8e85b3ff41e850f0bf3657f11
sha256: ccf063aa143480fcd1a5646eb4292ee5ca6ea5b998fd0eb6904e221d966325fe
sha512: b82f4f5857d23da21fcde4e69efc1e7688e5dbe284bde579f44cd346b6cf5229d2aeed57042cc6094701a171b1827a86bb621198d1867aa9e2a4655cf71db246
ssdeep: 3072:/kjzg6aPJiGPTUkOc4JBDyotg9RcYkgK05cp6V:c/1a3LUP7Byb9RcY3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0147 0x01ed

Mal/Generic-R + Troj/Steal-AUH also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44372115
FireEyeGeneric.mg.e9f1e17dbc2b23d3
McAfeeTrojan-FSUC!E9F1E17DBC2B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005725551 )
BitDefenderTrojan.GenericKD.44372115
K7GWTrojan ( 005725551 )
Cybereasonmalicious.a17a46
BitDefenderThetaGen:NN.ZexaF.34700.iqW@aWFzxoGG
CyrenW32/Kryptik.CGZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHHF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Generickdz-9789082-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
AlibabaTrojan:Win32/EmotetCrypt.c619d0ab
NANO-AntivirusTrojan.Win32.Zenpak.ibszol
ViRobotTrojan.Win32.Z.Kryptik.146432.HA
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareTrojan.GenericKD.44372115
SophosMal/Generic-R + Troj/Steal-AUH
F-SecureTrojan.TR/Crypt.Agent.nsflv
ZillyaTrojan.Zenpak.Win32.4392
TrendMicroTROJ_GEN.R002C0DK720
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Zenpak.efj
AviraTR/Crypt.Agent.nsflv
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Zenpak
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.MS!MTB
ArcabitTrojan.Generic.D2A51093
AhnLab-V3Trojan/Win32.Glupteba.R354833
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKD.44372115
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Backdoor.Mokes
ALYacTrojan.GenericKD.44372115
TACHYONTrojan/W32.Agent.146432.TW
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK720
TencentWin32.Trojan.Zenpak.Aoiz
YandexTrojan.Zenpak!sPu88p/mCeY
IkarusTrojan.Win32.Crypt
FortinetW32/GenericKDZ.F7A5!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.1207.Malware.Gen

How to remove Mal/Generic-R + Troj/Steal-AUH?

Mal/Generic-R + Troj/Steal-AUH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment