Malware

Mal/Generic-R + W32/Sivis-A removal tips

Malware Removal

The Mal/Generic-R + W32/Sivis-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + W32/Sivis-A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Mal/Generic-R + W32/Sivis-A?


File Info:

name: A5B6ED04144E3261A04A.mlw
path: /opt/CAPEv2/storage/binaries/f13e04e3a356708f107b48a300dcc97dfa625cb3b6989f33ab1d7d5e8e28f707
crc32: 75BA0683
md5: a5b6ed04144e3261a04a71dcf02c1b2f
sha1: 4d64665c89b113c5f49462aebccb9224b931e91d
sha256: f13e04e3a356708f107b48a300dcc97dfa625cb3b6989f33ab1d7d5e8e28f707
sha512: 15a60b79df53d517f0d6e6de76dd495099bb6ac78b9691c67890f8714bb0383edcde11ceee8982468a831befaeb0f0d6943244c43590976e27b1d0eb84f55952
ssdeep: 49152:oFhNGpWuFhNGpWrFhNGpW4FhNGpWuFhNGpWrFhNGpWJFhNGpWuFhNGpWrFhNGpWB:g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA85B72CF1D41DF6DCD48079DBE52691A760FC2A0210486732CCBA86A773943F676BE9
sha3_384: 8fe21bc4f640dbb63e0035d1a4937fcc7af3dd5b12db7f19f286d118a6d935924b3edbae6cdf897386195a92f1c9e1de
ep_bytes: 6814000000680000000068b8564000e8
timestamp: 2011-04-03 12:07:51

Version Info:

0: [No Data]

Mal/Generic-R + W32/Sivis-A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.81145
McAfeeW32/Sivis.gen.a
VIPREBehavesLike.Win32.Malware.eah (mx-v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderTrojan.GenericKDZ.81145
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.4144e3
CyrenW32/Sivis.A
SymantecW32.Suviapen
ESET-NOD32Win32/Agent.NBA
APEXMalicious
ClamAVWin.Trojan.Agent-6943819-1
KasperskyVirus.Win32.Agent.es
NANO-AntivirusVirus.Win32.Agent.klkgx
Ad-AwareTrojan.GenericKDZ.81145
SophosMal/Generic-R + W32/Sivis-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebWin32.Siggen.28
TrendMicroPE_SIVIS.A
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tz
FireEyeGeneric.mg.a5b6ed04144e3261
EmsisoftWin32.Sivis.A (B)
IkarusWin32.Sivis
JiangminTrojan/Cosmu.isk
AviraW32/Sivis.A
Antiy-AVLTrojan/Generic.ASVirus.180
MicrosoftVirus:Win32/Sivis.A
GDataWin32.Virus.Sivis.A
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Sivis.X2121
Acronissuspicious
VBA32BScope.Trojan.Cosmu
ALYacWin32.Sivis.A
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1444211799
TrendMicro-HouseCallPE_SIVIS.A
RisingVirus.Sivis!1.A647 (CLASSIC)
YandexTrojan.GenAsa!8BX67dEhxck
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Sivis.A!tr
BitDefenderThetaAI:FileInfector.0DC56C850D
AVGWin32:Agent-BCFZ [Trj]
AvastWin32:Agent-BCFZ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.W32.Agent.ES

How to remove Mal/Generic-R + W32/Sivis-A?

Mal/Generic-R + W32/Sivis-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment