Malware

About “Generik.DKLIWCT” infection

Malware Removal

The Generik.DKLIWCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DKLIWCT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.DKLIWCT?


File Info:

crc32: E44F5BBA
md5: 4b36ad7dc38eddf8582ee74097050930
name: 4B36AD7DC38EDDF8582EE74097050930.mlw
sha1: b48afe5af076aee2f2fc718f8a63cb3d1ea3aa50
sha256: 357e4b75ee1a15b65e556dcc3d216d5a67287fb7f6bd99580436ae701f8a40a0
sha512: 704e817ea7364fd9b61bc25ac379f45269778fdfa89e51d3d88a30dc6246612aecedc483c3e1a80e9ea5a211e944ee695613230bb7d5d1b2cb2c748d4a481b97
ssdeep: 12288:WANwRo+mv8QD4+0V16vD/OlUWqDBAXh5NHanGQcn:WAT8QE+krqDB85MGQQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Flash Machine
FileDescription: SIAP 1.0 Installation
FileVersion: 1.0
Comments:
CompanyName: Flash Machine
Translation: 0x0409 0x04e4

Generik.DKLIWCT also known as:

K7AntiVirusTrojan ( 0053c0d21 )
LionicTrojan.Multi.KeyLogger.4!c
CynetMalicious (score: 100)
CylanceUnsafe
K7GWTrojan ( 0053c0d21 )
Cybereasonmalicious.af076a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DKLIWCT
APEXMalicious
AvastWin32:Malware-gen
KasperskyVHO:Trojan-Spy.MSIL.KeyLogger.gen
NANO-AntivirusTrojan.Win32.Mlw.erkvue
TencentWin32.Trojan.Generic.Pdco
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaE.34104.Aq3@a0Nndiji
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!4B36AD7DC38E
IkarusTrojan.SuspectCRC
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
AVGWin32:Malware-gen

How to remove Generik.DKLIWCT?

Generik.DKLIWCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment