Malware

Generik.CPZILAV information

Malware Removal

The Generik.CPZILAV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CPZILAV virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests information related to installed instant messenger clients

How to determine Generik.CPZILAV?


File Info:

name: E373C5F9AD2C99BAE1B1.mlw
path: /opt/CAPEv2/storage/binaries/00d1e47980d450d147b21103c4ec8369dd3c67f0ccd29e1acb4730b38b1e8278
crc32: 1DD20434
md5: e373c5f9ad2c99bae1b19aad07f197ab
sha1: 4312b96001064b0271a1e95f90c036f63ed95576
sha256: 00d1e47980d450d147b21103c4ec8369dd3c67f0ccd29e1acb4730b38b1e8278
sha512: b8621a700e798c8dd1b89b7b1cab30a3d3b59ddeb27e2e338206d0d0e2c237c0a0e85d00bcc0338bdc5a7ca68cf9bcf149cda5e5aeac523a5010e2e092c2562b
ssdeep: 196608:hpLZMfYA9MXPv4yh3nTfaQO6NHVzl0HYr6mZu4R9dd3Mmnz1byp:7ZGJ9MXPQyh3TfaQOuxSYrpNtx8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BB63324F896CEF1E0365230D9F568F1D1741ED4FA7C979BA668FE0A7A713802467AC0
sha3_384: d4cfe81239ade1c7aa75843d6ecf9bed36d9a1f9ae30b2ffa257f89774f855036a7862380a4b5904f78410cb587aa00c
ep_bytes: e82f2b000050e83f3101000000000090
timestamp: 2007-05-08 11:09:56

Version Info:

0: [No Data]

Generik.CPZILAV also known as:

LionicTrojan.Win32.Genome.4!c
CylanceUnsafe
ZillyaTrojan.Katusha.Win32.22644
SangforTrojan.Win32.Agent.V09o
Cybereasonmalicious.9ad2c9
CyrenW32/Downloader.PLZV-8366
SymantecW32.SillyDC
ESET-NOD32a variant of Generik.CPZILAV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-722406
KasperskyTrojan.Win32.Genome.afjk
AlibabaTrojan:Win32/Genome.b2b46b55
NANO-AntivirusTrojan.Win32.Clicker.edixzx
RisingTrojan.Genome!8.229 (CLOUD)
SophosMal/Generic-S
ComodoMalware@#2ffysa7eny751
DrWebTrojan.Click2.7329
TrendMicroTROJ_GEN.R002C0OH522
McAfee-GW-EditionGenericR-JGL!F68AF750C384
Trapminesuspicious.low.ml.score
JiangminTrojan/Genome.dbwg
Antiy-AVLTrojan/Generic.ASMalwS.50E6
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Agent.QZQNS1
GoogleDetected
McAfeeArtemis!E373C5F9AD2C
VBA32Worm.AutoIt
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OH522
TencentWin32.Trojan.Genome.Kzfl
YandexTrojan.DL.Agent!jUDBVq9ArS8
IkarusTrojan.Win32.VB
FortinetW32/Genome.AFJK!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.CPZILAV?

Generik.CPZILAV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment