Malware

Generik.EMFLRZA (file analysis)

Malware Removal

The Generik.EMFLRZA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EMFLRZA virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Generik.EMFLRZA?


File Info:

name: 80FEC97B0DDF612E8453.mlw
path: /opt/CAPEv2/storage/binaries/d07029cb478fd45542f193e3abc5d9aa1e797f2eaaa5406fc703bcfc21b070bb
crc32: 200B647D
md5: 80fec97b0ddf612e8453bf6de637c1ae
sha1: d84a878f6e179c6c8aa3cc74780ae95c8f2a5c7f
sha256: d07029cb478fd45542f193e3abc5d9aa1e797f2eaaa5406fc703bcfc21b070bb
sha512: b9700a569842897721184755bd0daf7b0a64a18bd52fc09c4b7cddc8296599605ce5487c42b67cce95d51ae948c0b62370db6e3305c09e70778656be508911d4
ssdeep: 768:182HV0L3IKFU8oV6vonMouwr+EuijFlPchWBwFJ5wz:7HV0LcV6R/+xjFrBwFJyz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100D2D6539B1CB13ED45216B9A5A5A37209677C701B18F28FF2802E4B7CB86D2B93D347
sha3_384: 420c9ac3f1bf6648444c3aa1abe1f2895cafda59195f7f1cef87a937cda155e9fdee43757b65c97fd7e0e3692b1d3eb9
ep_bytes: 6a7068a02a0001e81d02000033db8d45
timestamp: 2008-07-02 12:38:31

Version Info:

Comments: Utility for setting a default MIDI device
CompanyName: Creative Technology Ltd
FileDescription: mididef
FileVersion: 2, 9, 0, 6
InternalName: mididef
LegalCopyright: Copyright© 2000-2005 Creative Technology Ltd
LegalTrademarks:
OriginalFilename: mididef.exe
PrivateBuild:
ProductName: Creative Audio Product
ProductVersion: 2, 9, 0, 6
SpecialBuild:
Translation: 0x0409 0x04b0

Generik.EMFLRZA also known as:

LionicTrojan.Win32.Microt.4!c
MicroWorld-eScanGen:Variant.Cerbu.167553
FireEyeGen:Variant.Cerbu.167553
McAfeeRDN/Generic.dx
Cylanceunsafe
SangforTrojan.Win32.Microt.Vzyo
AlibabaTrojan:Win32/Microt.19424a46
CyrenW32/Microt.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.EMFLRZA
KasperskyHEUR:Trojan.Win32.Microt.gen
BitDefenderGen:Variant.Cerbu.167553
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Microt.ka
TACHYONTrojan/W32.Microt.29184
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.psxmq
DrWebTrojan.MulDrop21.59792
VIPREGen:Variant.Cerbu.167553
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.Kudj.mm
EmsisoftGen:Variant.Cerbu.167553 (B)
GDataWin32.Trojan.PSE.19PF6GM
AviraTR/Redcap.psxmq
ArcabitTrojan.Cerbu.D28E81
ViRobotTrojan.Win.Z.Cerbu.29184.R
ZoneAlarmHEUR:Trojan.Win32.Microt.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R567795
ALYacGen:Variant.Cerbu.167553
MAXmalware (ai score=80)
MalwarebytesMalware.Heuristic.1001
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-21
RisingTrojan.Generic@AI.100 (RDML:SdM1hJ2tco69u+FyHzEjhg)
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generik.EMFLRZA?

Generik.EMFLRZA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment