Malware

Generik.EZWDUDG removal guide

Malware Removal

The Generik.EZWDUDG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EZWDUDG virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.EZWDUDG?


File Info:

name: 84572557AB53F906AD70.mlw
path: /opt/CAPEv2/storage/binaries/e911478e9261ad9e9fe7ee806fc3f8e4f261b79bfcfae20d4d63a469ef993ac4
crc32: C4CE4675
md5: 84572557ab53f906ad700dc305b5db22
sha1: c7bfb89312464a54eaf19f68582a333603c77776
sha256: e911478e9261ad9e9fe7ee806fc3f8e4f261b79bfcfae20d4d63a469ef993ac4
sha512: 93eb9667f4b5b695b9bf0942dfd00ddf23fa4a835627438c7b5079033229b5d2cc80a2607051bfb64b0c7e1bfada1794bda4fb20eca4e96ad6188b7e1a3649e0
ssdeep: 24576:PwWHhK2FjW8WVKsaGgl/oxlKAZhZakZXu4HzrHg8BepRxseBC:YWHhKejW8gKsZEWlF/fE4HzrA8mxb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB35339E9FD8411DF7F6027999B5B2C46E219F31EE0EFFD72484E8544C3A36186032A6
sha3_384: 3a5aa1307a59336e7a5a16dd4da4db78780ef00c746720177457f243d1f3b5a4c55914f0ff51e65f89723a6a683d7cd0
ep_bytes: 60be000046008dbe0010faff5783cdff
timestamp: 2016-10-31 14:47:57

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileVersion: 15.0.23.0
LegalCopyright: Copyright 2016 Avira Operations GmbH & Co. KG. All rights reserved.
OriginalFilename: ManagedFirewall_SysTray.exe
ProductName: Avira Swat Apl Rs
ProductVersion: 15.0.23.0
Translation: 0x0809 0x04b0

Generik.EZWDUDG also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ramy.4!c
MicroWorld-eScanAIT.Heur.Ramy.1.54C78CF9.Gen
ClamAVWin.Malware.Autoit-6992293-0
CAT-QuickHealTrojan.Autcobit
ALYacAIT.Heur.Ramy.1.54C78CF9.Gen
MalwarebytesGeneric.Malware.AI.DDS
VIPREAIT.Heur.Ramy.1.54C78CF9.Gen
SangforTrojan.Win32.Autcobit.Vqvc
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutCobit.2464a1e5
K7GWTrojan ( 700000111 )
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.EZWDUDG
APEXMalicious
CynetMalicious (score: 99)
BitDefenderAIT.Heur.Ramy.1.54C78CF9.Gen
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Autcobit.Vsmw
EmsisoftAIT.Heur.Ramy.1.54C78CF9.Gen (B)
F-SecureTrojan.TR/AutCobit.lkoev
DrWebTrojan.BtcMine.1084
TrendMicroTROJ_GEN.R002C0DGS23
McAfee-GW-EditionBehavesLike.Win32.DLSponsor.tc
Trapminemalicious.moderate.ml.score
FireEyeAIT.Heur.Ramy.1.54C78CF9.Gen
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.CDL9ON
AviraTR/AutCobit.lkoev
MAXmalware (ai score=88)
Antiy-AVLHackTool/Win32.Agent
ArcabitAIT.Heur.Ramy.1.54C78CF9.Gen [many]
MicrosoftTrojan:Win32/AutCobit
GoogleDetected
AhnLab-V3Trojan/Win32.Nymeria.C2495045
McAfeeArtemis!84572557AB53
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGS23
RisingTrojan.Generic@AI.95 (RDML:HvtGhTrYN1/TneoEH1vuUQ)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.214891654.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.EZWDUDG?

Generik.EZWDUDG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment