Malware

Generic.Malware.SIMeg.7CFFAFD7 (file analysis)

Malware Removal

The Generic.Malware.SIMeg.7CFFAFD7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Malware.SIMeg.7CFFAFD7 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Malware.SIMeg.7CFFAFD7?


File Info:

name: 041FB6543F8DD3E7D8DB.mlw
path: /opt/CAPEv2/storage/binaries/817a21ba4fc59f44992916e1b4925b1124b2ae75b2dfbd815acab48c2a0af5c7
crc32: 69CF7E95
md5: 041fb6543f8dd3e7d8dbce3c6807bec3
sha1: 51a25848fe231b39d5650c72594ef1bf4fd4e142
sha256: 817a21ba4fc59f44992916e1b4925b1124b2ae75b2dfbd815acab48c2a0af5c7
sha512: a2ed2ad82337e75dde5653b632aec0d00cdb9b5d170801f835f91ee2fba9bbe7bdb908563ed0439ea7bec9a71d2786e4aa601b370cf37dc0de23fc6de3367577
ssdeep: 384:bSuv01mhEByD6ciK/xXXfvNCKKJ4jxjbWM3FSUFeG865enBBY10owQadk:n8wKBGli2dv1CKKJ49fDsnB2Cona2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E43AEA1975EBA1DFB840EFE1A823724E74F60077DAB184A54764BC3E084F972218F95
sha3_384: 868235a66c20e085311c376c2addb22fe153a1b8851ddaf18b2edc6deceb449efbbc4bca16450e5cefab620867cfd1f9
ep_bytes: 4b432bf64b4381ce00204000c1c5f787
timestamp: 2030-10-10 11:14:36

Version Info:

0: [No Data]

Generic.Malware.SIMeg.7CFFAFD7 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.li46
DrWebWin32.XWorm.1
MicroWorld-eScanDeepScan:Generic.Malware.SIMeg.7CFFAFD7
FireEyeGeneric.mg.041fb6543f8dd3e7
CAT-QuickHealWorm.Duel.A.mue
ALYacDeepScan:Generic.Malware.SIMeg.7CFFAFD7
MalwarebytesMalware.Heuristic.1008
ZillyaWorm.LoveLetter.Win32.2254
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0040f5471 )
AlibabaVirus:Win32/EncPk.270984c9
K7GWEmailWorm ( 0040f5471 )
Cybereasonmalicious.43f8dd
BitDefenderThetaAI:Packer.59F607011D
VirITWorm.Win32.Luder.A
CyrenW32/Mixor.A
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/LoveLetter
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1365976
KasperskyPacked.Win32.Krap.ic
BitDefenderDeepScan:Generic.Malware.SIMeg.7CFFAFD7
NANO-AntivirusVirus.Win32.Glowa.gcpx
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.114919e5
EmsisoftDeepScan:Generic.Malware.SIMeg.7CFFAFD7 (B)
F-SecureWorm.WORM/Zhelatin.Gen
VIPREDeepScan:Generic.Malware.SIMeg.7CFFAFD7
TrendMicroTROJ_GEN.R03BC0CDU23
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qt
Trapminemalicious.high.ml.score
SophosMal/EncPk-JK
SentinelOneStatic AI – Suspicious PE
GDataDeepScan:Generic.Malware.SIMeg.7CFFAFD7
JiangminWorm/Luder.kv
GoogleDetected
AviraWORM/Zhelatin.Gen
Antiy-AVLTrojan/Win32.Agent
XcitiumWorm.Win32.LoveLetter.k@4w0pj0
ArcabitDeepScan:Generic.Malware.SIMeg.7CFFAFD7
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirus:Win32/Duel.A@mm
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Mixor.R43516
McAfeeGeneric-FAGI!041FB6543F8D
MAXmalware (ai score=100)
VBA32Virus.Win32.Luder.A
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CDU23
RisingHack.Win32.Mixcode.a (CLASSIC)
YandexWorm.Loveletter.Gen
IkarusVirus.Win32.Heur
FortinetW32/LoveLetter.JK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Malware.SIMeg.7CFFAFD7?

Generic.Malware.SIMeg.7CFFAFD7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment