Malware

Generik.DVERRPY removal tips

Malware Removal

The Generik.DVERRPY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DVERRPY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Generik.DVERRPY?


File Info:

name: 78669414280159D56F99.mlw
path: /opt/CAPEv2/storage/binaries/b5332893c1728547159945b3b5f0e6b500557a6b33725b995734fb77529d5ad9
crc32: 8A1C6AD6
md5: 78669414280159d56f995d8d6e85bdb5
sha1: 041891e3bb64ea38c6e9b634e238fe5139697749
sha256: b5332893c1728547159945b3b5f0e6b500557a6b33725b995734fb77529d5ad9
sha512: 4939d68042490e92d250df5dc310a5186bcb6cac62959a23fb0505c1ac27ab41de39a018716ba99452df25449adda9b00985b3fbe36ad13aeb78e05e8f6aa980
ssdeep: 24576:RdY+zcRZqn00b7R6hpNaa11h+QZeyZdJE7FiVmEpAB4xW51E2tzB:RdYXZqn9bNiCghZw7FiVm8A0W5tt1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9352319FF928C32C5124B358C1BD620E9367F142A3850D633ED7F9DA9F618B5A1C2B6
sha3_384: f51faefa302a75aff7483c87a4447fbfa57adcebb74526a83449a78f866aac090e15104a42f8a20fca57adfa067e7ee6
ep_bytes: 558bec83c4f0b8187d4100e8f0aafeff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: WinRAR
FileDescription: Wenpany 6.0.0 Installation
FileVersion: 6.0.0
LegalCopyright: WinRAR
Translation: 0x0409 0x04e4

Generik.DVERRPY also known as:

LionicTrojan.Win32.VB.m!c
DrWebTrojan.DownLoader3.45791
MicroWorld-eScanTrojan.GenericKD.37202631
FireEyeTrojan.GenericKD.37202631
ALYacTrojan.GenericKD.37202631
CylanceUnsafe
SangforTrojan.Win32.AGEN.1034766
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Generic.e7bb9685
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.428015
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.DVERRPY
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.VB.nrg
BitDefenderTrojan.GenericKD.37202631
NANO-AntivirusTrojan.Win32.VB.gwwru
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Vb.Dplw
Ad-AwareTrojan.GenericKD.37202631
SophosAdLoad (PUA)
VIPRETrojan.GenericKD.37202631
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.37202631 (B)
GDataTrojan.GenericKD.37202631
WebrootW32.Gen.BT
GoogleDetected
AviraBDS/VB.nrg.3
Antiy-AVLTrojan/Generic.ASMalwS.12A
KingsoftWin32.Troj.VB.nr.(kcloud)
ArcabitTrojan.Generic.D237AAC7
ZoneAlarmBackdoor.Win32.VB.nrg
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!786694142801
VBA32TrojanDropper.Agent
RisingTrojan.Sisproc!8.830 (TFE:5:sXEskaBfcKJ)
YandexBackdoor.VB!qQgxs86UXTE
IkarusBackdoor.Win32.VB
MaxSecureTrojan.Malware.2375964.susgen
FortinetW32/VB.NRG!tr.bdr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Generik.DVERRPY?

Generik.DVERRPY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment