Malware

What is “Generik.CXTWGEE”?

Malware Removal

The Generik.CXTWGEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CXTWGEE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Mimics the system’s user agent string for its own requests
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A system process is generating network traffic likely as a result of process injection
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
beman.at

How to determine Generik.CXTWGEE?


File Info:

crc32: EF1A75DE
md5: 328904a3bd9984a98ceb660e36b5b450
name: 328904A3BD9984A98CEB660E36B5B450.mlw
sha1: a2ff2a1f554866a30d5e89381af2897df6d3914e
sha256: 5bf6b85036d20f71de8cbbdcc7a1853b6970505a4e4c7633d58a2b815f2a9d24
sha512: f07fc640c065e511088e3b414f9da5c8853d30b0a1dec1bf68f96b7c2ce5cd3dc90d06f2fd31f8b9702e2fdfc36a2257f3b75912aded08caf1cc209374ef7a21
ssdeep: 3072:qAe+3aJpqWXTBuQPv50oyjZWEvqCI71R7zxgWRkOZ14Eh+1q11X7sGnyN/ohvk0:5B+pqU7WNZjqFRruqmqT4/ohvT
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Generik.CXTWGEE also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Zbot.l!c
DrWebTrojan.PWS.Sphinx.32
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.4396210
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanSpy:Win32/Cerber.ee4c3d3e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3bd998
SymantecRansom.Cerber
ESET-NOD32a variant of Generik.CXTWGEE
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Zbot.yamd
BitDefenderTrojan.GenericKD.4396210
NANO-AntivirusTrojan.Nsis.Zbot.elohjh
MicroWorld-eScanTrojan.GenericKD.4396210
TencentWin32.Trojan-spy.Zbot.Liqr
Ad-AwareTrojan.GenericKD.4396210
SophosMal/Generic-R + Mal/Cerber-AA
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.cc
FireEyeGeneric.mg.328904a3bd9984a9
EmsisoftTrojan.GenericKD.4396210 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1131933
MicrosoftVirTool:Win32/Obfuscator
GDataTrojan.GenericKD.4396210
McAfeeArtemis!328904A3BD99
MAXmalware (ai score=87)
VBA32TrojanSpy.Zbot
PandaTrj/CI.A
FortinetW32/Zbot.YAMD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.CXTWGEE?

Generik.CXTWGEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment