Malware

Generik.DGUCTIF removal instruction

Malware Removal

The Generik.DGUCTIF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DGUCTIF virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generik.DGUCTIF?


File Info:

name: 7E383B781944F57C5D9E.mlw
path: /opt/CAPEv2/storage/binaries/7ed9969a53b72c2cb232b147eb0afade9e0397d391ccedde1bd2c1962e55efb3
crc32: 559B578A
md5: 7e383b781944f57c5d9edc403bf11377
sha1: 110e89691372e4b6033a756dd56db9344995675c
sha256: 7ed9969a53b72c2cb232b147eb0afade9e0397d391ccedde1bd2c1962e55efb3
sha512: 31cd320241bcfaf402c85bd80ba6b49e5aeb5741e343ddf79e036c219edb54b4021fef80c54eeb0de17df22cc2118593b9ed56a727328bc2776c154965d5d536
ssdeep: 24576:xMmcDBQ8SJuXXSSKONy3M24eQfoEuO24HVp6+y+4cySuLsowmnc2DVn/c:mmcD9SJyCxgf1Fbp6f9517Hnci5c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D45336607C0905AE8CE8DF0A2734B8F9356EF4162E46B0717552B37BC29683EC66B17
sha3_384: 404d5aa7d52e8546f8bf0d7dcc50fd28a5ca64298395b46d9ef84ca0a27aced11e5396c5773f1cb42a7c711cb95ae0e7
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:23

Version Info:

Comments: 美女汇安装包
CompanyName: 北京品女网络信息技术有限公司
FileDescription: 美女汇安装包
FileVersion: 1.0.0.0
InternalName: 美女汇
ProductName: 美女汇
Translation: 0x0804 0x03a8

Generik.DGUCTIF also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeTrojan.GenericKD.65364445
CAT-QuickHealTrojan.NSIS.Startpage.AC
McAfeeArtemis!7E383B781944
Cylanceunsafe
VIPRETrojan.GenericKD.65364445
SangforAdware.Win32.Agent.Vz32
CrowdStrikewin/grayware_confidence_70% (W)
AlibabaTrojan:Win32/StartP.3ca1fd71
VirITTrojan.Win32.DownLoader11.BMDF
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.DGUCTIF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Startpage-6592
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.65364445
NANO-AntivirusTrojan.Win32.RiskGen.dhziop
MicroWorld-eScanTrojan.GenericKD.65364445
AvastWin32:Adware-gen [Adw]
EmsisoftTrojan.GenericKD.65364445 (B)
F-SecureProgram.APPL/Meinhudong.idu
ZillyaAdware.Agent.Win32.14245
McAfee-GW-EditionBehavesLike.Win32.Exent.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S (PUA)
IkarusTrojan.SuspectCRC
AviraAPPL/Meinhudong.idu
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumApplicUnwnt.Win32.Mnhb.A@59folx
ArcabitTrojan.Generic.D3E561DD
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.65364445
GoogleDetected
AhnLab-V3Adware/Win32.PornTool.R119328
ALYacTrojan.GenericKD.65364445
MAXmalware (ai score=80)
VBA32Trojan.Occamy
MalwarebytesGeneric.Trojan.Downloader.DDS
PandaTrj/CI.A
RisingAdware.StartPage!1.BEF9 (CLASSIC)
YandexTrojan.GenAsa!D6w2/ue8EPY
FortinetW32/Dloader.NSIS!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Generik.DGUCTIF?

Generik.DGUCTIF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment