Malware

Generik.DUWQDVY malicious file

Malware Removal

The Generik.DUWQDVY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DUWQDVY virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Possible date expiration check, exits too soon after checking local time
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Generik.DUWQDVY?


File Info:

name: 4A95F9312F40C69494B1.mlw
path: /opt/CAPEv2/storage/binaries/5fbce2f6e5883ae6f76fad85ee4f6df5865ac813de19fd143b1c870dbb1e366c
crc32: D99576D3
md5: 4a95f9312f40c69494b1065d02169dc0
sha1: 582b724fcd57eb0d1dcb9b48dc889bc2e241c1c1
sha256: 5fbce2f6e5883ae6f76fad85ee4f6df5865ac813de19fd143b1c870dbb1e366c
sha512: 4a0342fc217f0b6375c6d1dbe8cd9a71157b5726cc5cce6591fca830305fad09639995b68184b320f4ee924581627deca6fff41c20c8999ba7fa657b12c60224
ssdeep: 24576:u3KFcu6zfdQcK+d4UlW/I5I5GMvI8d8f5e8/++VrG6uBa2A:KKufdQb04UlW0qW5ec+AGHsP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1872501B7619194A5C55A2B30F4700F4B363CD9340A50B95FB10EF2BEAD1D29C8EF876A
sha3_384: 203cacc0ac68715ca50e7113ce9d947f62e706223e609b4f7df25930b5fa1d363982d3c7470fe68e04500cfc18e64bbb
ep_bytes: e82f040000e97afeffffc3558becff75
timestamp: 2020-01-20 12:15:03

Version Info:

0: [No Data]

Generik.DUWQDVY also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.377841
McAfeeArtemis!4A95F9312F40
CylanceUnsafe
ZillyaTrojan.SpyEyes.Win32.14890
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/SpyEyes.3b1147a3
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.12f40c
ArcabitTrojan.Razy.D5C3F1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DUWQDVY
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.bjys
BitDefenderGen:Variant.Razy.377841
NANO-AntivirusTrojan.Win32.Steam.hbcnxm
RisingTrojan.Detplock!8.4A0D (TFE:5:ILEI1sNKiDT)
Ad-AwareGen:Variant.Razy.377841
SophosGeneric ML PUA (PUA)
DrWebTrojan.PWS.Steam.17507
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.4a95f9312f40c694
EmsisoftGen:Variant.Razy.377841 (B)
JiangminTrojan.Snojan.coc
AviraHEUR/AGEN.1237796
Antiy-AVLTrojan/Generic.ASMalwS.2FECF5B
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmTrojan-Spy.Win32.SpyEyes.bjys
GDataGen:Variant.Razy.377841
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34182.7uW@a0DKlSbi
ALYacGen:Variant.Razy.377841
MAXmalware (ai score=82)
VBA32BScope.Trojan.Snojan
TencentWin32.Trojan-spy.Spyeyes.Pezt
YandexTrojan.GenAsa!DvJr88h2dZs
SentinelOneStatic AI – Malicious PE
FortinetW32/Generik.DUWQDVY!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.DUWQDVY?

Generik.DUWQDVY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment