Malware

Generik.GWDJZXI (file analysis)

Malware Removal

The Generik.GWDJZXI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GWDJZXI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.GWDJZXI?


File Info:

crc32: 18AE3614
md5: 4d4bc0c39fc901c1a86ef43fc3bf189a
name: 4D4BC0C39FC901C1A86EF43FC3BF189A.mlw
sha1: 4736a94c30917e695ebf58f674632575e383d571
sha256: 1db3436f625cebe977fb3a664dda374d3873e50d4f4f46c50a258949905f7494
sha512: 62bcb7214a1f7c3143ee69f4b188cfea38369d2d7b736891bc1a280334cfd2c31d994f99a1da890203ea638ff17b82c4481f765de4bb9ff3b37dcdc11f46dee6
ssdeep: 12288:pY20AljdZgBPfKf8+QxAogJfqsUsz0cX0eqUW7Yo63X7ZqNFi2fMM7Ms:e20gPgFKU+QxAVBbIcXT07YoCSNhp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.GWDJZXI also known as:

BkavW32.AIDetect.malware2
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.c30917
ESET-NOD32a variant of Generik.GWDJZXI
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.4d4bc0c39fc901c1
MicrosoftTrojan:Script/Phonzy.C!ml
McAfeeArtemis!4D4BC0C39FC9
IkarusTrojan.Inject
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwYDLmUA

How to remove Generik.GWDJZXI?

Generik.GWDJZXI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment