Malware

Mal/Generic-S + Troj/Azov-A removal guide

Malware Removal

The Mal/Generic-S + Troj/Azov-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Azov-A virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Troj/Azov-A?


File Info:

name: 9C52A1A53BD9590F1B62.mlw
path: /opt/CAPEv2/storage/binaries/13fc82e69611b4d01ee87974b5700ba3952e2519eceb2ca304270037c062f175
crc32: 9085AC36
md5: 9c52a1a53bd9590f1b62c37f641be90e
sha1: 1c40cef95254d5ef28ee9adf178f4a32b91e8d02
sha256: 13fc82e69611b4d01ee87974b5700ba3952e2519eceb2ca304270037c062f175
sha512: 86654607d73042c78f5aede7f4a72e5adb701127eb93aca26ae3163d601d4dc3d2ff637f743b59d7e176e5e11dfdb95788dcbfe86cf3585de943a549c83f124c
ssdeep: 3072:tuTO4rRZie/1vX1mGG3XscjfU39sq+ZDPUEMTlqoH0kgyF74BmN/cOXpxnAS:tkZN/1vFmGGnJs9AZDPFMTHHFsdOXpOS
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T14904AF47B7F40069D07AD1B6C8F6471A97B1BC514B7153CF2A9986AA6F33BE08D34322
sha3_384: 5a110b0af67d64e0edae5ab4c08173a2c6da43edbae0deec51fe8462df5361646f85a92d613d3b5df9bc56b3c9a880d4
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2019-11-05 20:50:30

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows® installer
FileVersion: 5.0.7601.24535 (win7sp1_ldr_escrow.191105-1059)
InternalName: msiexec
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: msiexec.exe
ProductName: Windows Installer - Unicode
ProductVersion: 5.0.7601.24535
Translation: 0x0409 0x04b0

Mal/Generic-S + Troj/Azov-A also known as:

DrWebWin32.HLLP.Azov.2
MicroWorld-eScanTrojan.Ransom.Agent.DT
FireEyeTrojan.Ransom.Agent.DT
ALYacTrojan.Ransom.Agent.DT
CylanceUnsafe
VIPRETrojan.Ransom.Agent.DT
K7AntiVirusTrojan ( 0059a88d1 )
BitDefenderTrojan.Ransom.Agent.DT
K7GWTrojan ( 0059a88d1 )
ArcabitTrojan.Ransom.Agent.DT
CyrenW64/Ipamor.A
SymantecML.Attribute.HighConfidence
ESET-NOD32Win64/Filecoder.GG
ClamAVWin.Ransomware.Generic-9977226-0
RisingRansom.Agent!8.6B7 (TFE:2:U9tOTBNOHOO)
Ad-AwareTrojan.Ransom.Agent.DT
SophosMal/Generic-S + Troj/Azov-A
McAfee-GW-EditionRDN/Ransom
EmsisoftTrojan.Ransom.Agent.DT (B)
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Blocker.urx
GoogleDetected
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C73A
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Ransom.Agent.DT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R533795
MalwarebytesRansom.Azov
TencentTrojan-Ransom.Win64.Agent.ya
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen
AvastWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Mal/Generic-S + Troj/Azov-A?

Mal/Generic-S + Troj/Azov-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment