Malware

Generik.IWKWKZ (file analysis)

Malware Removal

The Generik.IWKWKZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.IWKWKZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to execute suspicious powershell command arguments
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Generik.IWKWKZ?


File Info:

name: 7DC9C9091A292E92B862.mlw
path: /opt/CAPEv2/storage/binaries/e8536e3bec2b6dd548e9b3d5667cd9542b2864e5abb79c91d8251e3c5af45402
crc32: 41EBEFCE
md5: 7dc9c9091a292e92b862a23190c74949
sha1: f873e6716817ce57c519faac8305e6ad4ea75870
sha256: e8536e3bec2b6dd548e9b3d5667cd9542b2864e5abb79c91d8251e3c5af45402
sha512: 475a304988df325125ed2d68889b302c61d6472b4a62aa09c0b9dc68d2b2e97bbfb8ba920176f3ef02209962de0d712e9e4b8da1494f13012723074bc029ae5d
ssdeep: 49152:3c7vS/qREPoh7k+Svir8a0PwUKXe79Dg2qX7MJ0BcQrxQhOBJoWh2uh59:3c7S/qReacvFHty5X7U0BckLYu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AE50066629A80AEF9F0FE3D44A5D74A31E039E33D433AC2E6C96D1B406F167EE35051
sha3_384: a32f86155f4e983b3e3937120005605b1931c5d2faf9e5e9e881fe4f172c3e566cbff7c715f69b5b39995ec6ee6a0561
ep_bytes: e800070000e9000000006a5868687240
timestamp: 2000-11-24 11:50:57

Version Info:

Comments: Her Name Software
CompanyName: Her Name Software
FileDescription: Her Name Software
LegalCopyright: Her Name Software
LegalTrademarks: Her Name Software
ProductName: Her Name Software
FileVersion: 6.0.228
ProductVersion: 6.0.228
InternalName: Her Name
OriginalFilename: Her Name.exe
Translation: 0x0407 0x04b0

Generik.IWKWKZ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.trGK
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38132630
FireEyeGeneric.mg.7dc9c9091a292e92
McAfeeArtemis!7DC9C9091A29
CylanceUnsafe
K7AntiVirusTrojan ( 0058b0041 )
AlibabaTrojan:Win32/Generic.421ce4c7
K7GWTrojan ( 0058b0041 )
Cybereasonmalicious.16817c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.IWKWKZ
Paloaltogeneric.ml
KasperskyTrojan.Win32.Pits.wh
BitDefenderTrojan.GenericKD.38132630
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.38132630
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
EmsisoftTrojan.GenericKD.38132630 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.NGASNZ
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D245DB96
ViRobotTrojan.Win32.Z.Highconfidence.3274240
MicrosoftPUA:Win32/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4280705
ALYacTrojan.GenericKD.38132630
MalwarebytesBackdoor.Quasar
APEXMalicious
RisingDownloader.BitsAdmin!1.D0D1 (CLASSIC)
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Generik.IWKWKZ?

Generik.IWKWKZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment