Malware

About “Generik.IIAWXGO” infection

Malware Removal

The Generik.IIAWXGO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.IIAWXGO virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Generik.IIAWXGO?


File Info:

name: 85A317E481A14D79E992.mlw
path: /opt/CAPEv2/storage/binaries/b6d57bfa484b85716454fb936e2004ed937a80077f3942d962313391a18d9da7
crc32: 3214C0C2
md5: 85a317e481a14d79e9923fdd7352a6dc
sha1: a3f3336e8aaea23001df66763c4bedc845f8e555
sha256: b6d57bfa484b85716454fb936e2004ed937a80077f3942d962313391a18d9da7
sha512: 7156bab7fc6986358770e2026cd24d64c23bf507293340cba00aa0dd86b6060d392ae0fe115cf5688e01a841b850a8010c7efdaaaf0f1a3b8d9ad00cd3ca4674
ssdeep: 49152:oZ38AN/1q2GG7LfjCTevHTyM8UkJXnuqGyk+Tdi8WEYsPttr6D4vl5z71BwkxzCb:od8AN9GG7LfjCTe56XLGyk+T7YsPO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12336B50A98D9A04BC93983F292D53D277B7075A263838FCAD77C89EC79473A1E60505F
sha3_384: 327241d0498c8f5942996c26addf156502b5c95f62642a9cae91e48eb510a812d757eed29ca7c8f67cf442ea1b008862
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-15 08:19:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Client.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Client.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Generik.IIAWXGO also known as:

LionicTrojan.MSIL.Crysan.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61330682
FireEyeGeneric.mg.85a317e481a14d79
ALYacTrojan.GenericKD.61330682
SangforBackdoor.Msil.Crysan.Vam6
AlibabaBackdoor:MSIL/Crysan.c187b44b
BitDefenderThetaGen:NN.ZemsilF.34606.@t0@a4mjEJf
CyrenW32/ABRisk.OHED-9101
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.IIAWXGO
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderTrojan.GenericKD.61330682
AvastWin32:Trojan-gen
TencentMsil.Backdoor.Crysan.Ebgt
Ad-AwareTrojan.GenericKD.61330682
EmsisoftTrojan.GenericKD.61330682 (B)
VIPRETrojan.GenericKD.61330682
McAfee-GW-EditionArtemis
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.Agent.XMBB92
GoogleDetected
AviraBDS/Redcap.mlwao
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!85A317E481A1
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002H0CHI22
RisingBackdoor.Crysan!8.10ECA (CLOUD)
IkarusTrojan.MSIL.Agent
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Generik.IIAWXGO?

Generik.IIAWXGO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment