Malware

Generik.GSTZSWR malicious file

Malware Removal

The Generik.GSTZSWR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GSTZSWR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.GSTZSWR?


File Info:

crc32: 552D9C00
md5: a43d708fc29827e59a1a72e482b12d78
name: A43D708FC29827E59A1A72E482B12D78.mlw
sha1: 66e8a3641b39f88a132bb9ef6a142d1ba5df04e7
sha256: 2bdbef79539936e98e519119ba6942f1eeaeb597f7bac345138ebdbd0d190703
sha512: af3b010ce075f8dd4824fc3fa682f0d15da044cdb3cad49f3c4de6c3091bfe7c144aed8856f991667cb0a9a0acad645d5c2231f7ca6b39febecf3267899d766b
ssdeep: 6144:xcqJqHFHyiogMNUcBiXp2Z2+igxlMy6y:xGFvobN7Bi4z8y
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: NeroDisc
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NeroDiscMergeWrongDisc
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: NeroDiscMergeWrongDisc Application
OriginalFilename: NeroDiscMergeWrongDisc.exe
Translation: 0x0409 0x04e4

Generik.GSTZSWR also known as:

K7AntiVirusTrojan ( 0051e0631 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Zusy.320442
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Tovicrypt.776f1b72
K7GWTrojan ( 0051e0631 )
Cybereasonmalicious.fc2982
CyrenW32/S-8ecc9d92!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.GSTZSWR
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.320442
NANO-AntivirusTrojan.Win32.CryptXXX.evpaaz
MicroWorld-eScanGen:Variant.Zusy.320442
TencentWin32.Trojan.Generic.Lkdp
Ad-AwareGen:Variant.Zusy.320442
SophosMal/Generic-S
ComodoMalware@#kwsyyxqspefi
BitDefenderThetaGen:NN.ZexaF.34142.vy0@aW5zsizi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Crypmic-1
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.a43d708fc29827e5
EmsisoftGen:Variant.Zusy.320442 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1144000
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22C4396
MicrosoftRansom:Win32/Tovicrypt.A
GDataGen:Variant.Zusy.320442
Acronissuspicious
McAfeeRansomware-GJA!A43D708FC298
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.2451378745
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Crypmic-1
RisingTrojan.Generic@ML.100 (RDML:dv+TAQMfbVJoX82pxe1x6A)
YandexTrojan.GenAsa!QApzGEBtZck
IkarusTrojan-Ransom.Locky
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.GSTZSWR?

Generik.GSTZSWR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment