Malware

Generik.CUKCVUC (file analysis)

Malware Removal

The Generik.CUKCVUC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CUKCVUC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates known CypherIT/Frenchy Shellcode mutexes
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.CUKCVUC?


File Info:

name: 4F01A0E4CB02E8478D07.mlw
path: /opt/CAPEv2/storage/binaries/86655feecfc30d93e5b565aa0c9c8f9a139d2e85094e7bbb6405289d23abec0e
crc32: 469984F7
md5: 4f01a0e4cb02e8478d07e976e5388cde
sha1: f2af5608a0c2068560c48117f7f5282dc52b4be3
sha256: 86655feecfc30d93e5b565aa0c9c8f9a139d2e85094e7bbb6405289d23abec0e
sha512: dcae1f0368639005510b553db8bb757bd785b5ac4775c8bd1feeeeccca98d97651680980156d0b2c2948a77795936acc3d7be4f7687cf08d59ef3f0c6c7fc6d0
ssdeep: 24576:rAHnh+eWsN3skA4RV1Hom2KXMmHaDuQ7X5xu35:Gh+ZkldoPK8YaDuQ7Ly
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B359C0273968C26FFAEB1739B56B20156BDE9253123CD3F12981D78A9701A11E3D36F
sha3_384: 72cfff94390b8881f86400ff36e9d42fee5a9c9ec912aa4b3e955f98c400331343c46c22c26d314a9be9ead1094c61a4
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-09-16 23:06:48

Version Info:

Translation: 0x0809 0x04b0

Generik.CUKCVUC also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.31426
MicroWorld-eScanTrojan.GenericKD.32467985
ClamAVWin.Trojan.Autoit-7168880-0
FireEyeGeneric.mg.4f01a0e4cb02e847
CAT-QuickHealTrojan.AutoIt.Injector.ZZ
ALYacTrojan.GenericKD.32467985
MalwarebytesGeneric.Malware.AI.DDS
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Script/AutoitInject.1a4765c0
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/Autoit.G.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Generik.CUKCVUC
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.32467985
NANO-AntivirusTrojan.Win32.Mlw.gagzsw
AvastAutoIt:Dropper-DL [Trj]
TencentWin32.Trojan.Generic.Kajl
SophosMal/Generic-S
F-SecureDropper.DR/AutoIt.Gen8
VIPRETrojan.GenericKD.32467985
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
EmsisoftTrojan.GenericKD.32467985 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.32467985
WebrootW32.Malware.Mlpe
AviraDR/AutoIt.Gen8
ArcabitTrojan.Generic.D1EF6C11
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/AutoitInject.BH!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_AutoInj.R272810
McAfeeArtemis!4F01A0E4CB02
MAXmalware (ai score=87)
VBA32Trojan.AutoitInject
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
RisingTrojan.Obfus/Autoit!1.BCF5 (CLASSIC)
IkarusTrojan-Spy.FormBook
MaxSecureTrojan.Malware.7164915.susgen
AVGAutoIt:Dropper-DL [Trj]
Cybereasonmalicious.4cb02e
DeepInstinctMALICIOUS

How to remove Generik.CUKCVUC?

Generik.CUKCVUC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment