Malware

Generik.GRRPYWL removal guide

Malware Removal

The Generik.GRRPYWL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GRRPYWL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Detects the presence of Windows Defender AV emulator via files
  • Clears Windows events or logs
  • Harvests cookies for information gathering

How to determine Generik.GRRPYWL?


File Info:

name: 05F31A3259242A4D998A.mlw
path: /opt/CAPEv2/storage/binaries/863558e164b10d3097948dea67355a2de820154056e9295b54845d4dc826a104
crc32: E0DD0C72
md5: 05f31a3259242a4d998a95dbe05f4692
sha1: cd8e3e01beb69e13907f5c8db0c18d08e44c9a63
sha256: 863558e164b10d3097948dea67355a2de820154056e9295b54845d4dc826a104
sha512: 270d68ead2dc95f60df91d03db29f75808ff66dbc4e72bd14b9a1426963b88aa6285b0932eabaa0a674d3b5558922354418695c5e73c7ccd4cc5648e29f7e580
ssdeep: 768:qzdtcAAayQ6I6Ro1dwwGl8940Xq3jk33H4XkwZYriO:q0AC66Ro/4iq3jcsgiO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB436C0BBEA38621C5A64BF00A2B166BDB735B12C37042DBD75CFA196FB11D2C93C159
sha3_384: c344a953d75cd2c4b96ca442a32347f35ad48cf4075d72d14fbb18e8915a247689cf6320afd768846abb355f460693fe
ep_bytes: 68c80000006800000000683cb14000e8
timestamp: 2010-11-08 13:12:07

Version Info:

0: [No Data]

Generik.GRRPYWL also known as:

BkavW32.AIDetect.malware1
LionicTrojan.BAT.Agent.lA7V
ALYacTrojan.GenericKDZ.60123
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/KillFiles.37621a4d
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.259242
CyrenBAT/KillWin.W
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.GRRPYWL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.KillFiles
BitDefenderTrojan.GenericKDZ.60123
NANO-AntivirusTrojan.Win32.Mlw.gjneym
MicroWorld-eScanTrojan.GenericKDZ.60123
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Killfiles.Hpb
Ad-AwareTrojan.GenericKDZ.60123
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R002C0PHB20
McAfee-GW-EditionBehavesLike.Win32.Generic.qm
FireEyeGeneric.mg.05f31a3259242a4d
EmsisoftTrojan.GenericKDZ.60123 (B)
IkarusTrojan.Win32.Ransom
GDataTrojan.GenericKDZ.60123
AviraTR/Dropper.Gen
ArcabitTrojan.Generic.DEADB
ViRobotDropper.S.Agent.58368.I
ZoneAlarmHEUR:Trojan.Win32.KillFiles
MicrosoftTrojan:Win32/Occamy.C86
AhnLab-V3Malware/Win32.Generic.C3588238
McAfeePolyPatch-UPX
MAXmalware (ai score=100)
VBA32Trojan.KillFiles
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0PHB20
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.KillFiles!4PbTD+xCNFI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.8040.susgen
FortinetW32/Generic.AC.2B8F21!tr
AVGFileRepMalware [Misc]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.GRRPYWL?

Generik.GRRPYWL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment