Malware

Generik.FDWMEGY (file analysis)

Malware Removal

The Generik.FDWMEGY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.FDWMEGY virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Creates a hidden or system file
  • CAPE detected the caliber malware family
  • Deletes executed files from disk

How to determine Generik.FDWMEGY?


File Info:

name: 69D7AE1A8004630F1440.mlw
path: /opt/CAPEv2/storage/binaries/0d79e8b0a06de556389967a1b4c542a28a0d4504647626c74d66fb1d58892c67
crc32: B0834427
md5: 69d7ae1a8004630f14401fa41d7d683e
sha1: e7cda0b99cf94e3793c66f2961c6ca1db09bcced
sha256: 0d79e8b0a06de556389967a1b4c542a28a0d4504647626c74d66fb1d58892c67
sha512: fe93ee66858431d9513ffb86bbfd80650ad07a2e5bf384abdd5ac624a67fb340d24ae60573b85ef48fafb9c695e9455b307684d1ea5b58edda8306e88cfadb8a
ssdeep: 49152:884I3LHZQbFSSPWZ8pr4rG2QWvXCzViQzc2/RFqKI5wP5h3Lld3jvxz2jjkjqAM2:8AISSPWZ8pr4rhQWvvGjv3j31zCjZOL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16EE53302BAC45572D2621A310925BBB9657CB8201F39DF9F93A08E6ED7710C1B770BB7
sha3_384: 9a17aa170f089f7c442643f10237b1271f554249c0e09ebee92fdef8d3b4d5c37f6a17fdb2df64ec3497d1f06d2607cd
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Generik.FDWMEGY also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.NanoBot.trQD
MicroWorld-eScanTrojan.Rasftuby.Gen.14
FireEyeGeneric.mg.69d7ae1a8004630f
McAfeeArtemis!69D7AE1A8004
CylanceUnsafe
AlibabaTrojan:Win32/GenSteal.2c31c2f9
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Rasftuby.Gen.14
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.FDWMEGY
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.Rasftuby.Gen.14
AvastWin32:Malware-gen
Ad-AwareTrojan.Rasftuby.Gen.14
VIPRETrojan.Rasftuby.Gen.14
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
AviraTR/AD.GenSteal.lsszy
Antiy-AVLTrojan/Generic.ASCommon.24D
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.Z.Rasftuby.3069950
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Rasftuby.Gen.14
CynetMalicious (score: 99)
Acronissuspicious
ALYacTrojan.Rasftuby.Gen.14
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002H09H122
AVGWin32:Malware-gen
Cybereasonmalicious.a80046
PandaTrj/CI.A

How to remove Generik.FDWMEGY?

Generik.FDWMEGY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment