Malware

What is “Generik.LCAWDSY”?

Malware Removal

The Generik.LCAWDSY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LCAWDSY virus can do?

  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.LCAWDSY?


File Info:

name: A515DF16A5D71C01280C.mlw
path: /opt/CAPEv2/storage/binaries/2819937f063b99d5c716e6b92d54431d689086c46c6946871550a6bc383518be
crc32: A6C13AF7
md5: a515df16a5d71c01280cf5bb6709f439
sha1: 76a4617860fd86136cf430818889aae442179863
sha256: 2819937f063b99d5c716e6b92d54431d689086c46c6946871550a6bc383518be
sha512: 74243cf0bb5f32089dbe41dfd8726654d790cd35d750c6c2ed12a8255a62fb5de9d75f0fdd6d828c198c5c29e6aea81efc308c5a0523bf516076fa87407cd8ff
ssdeep: 98304:imEBrT2b5mXLKZCWhNNKAXsmhj0UiDWTViYAHZMKyM:imQ2sI/NNN/1mWBAC0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E2633D798E47453C7D131FA6323B087C575F9365840FA9D0AA45B3FA320BC788B6A89
sha3_384: 169eda92d749a93608d0928e786bca003b3aeaff680829d2f3253bfc1bdcc7f1c438709f2c3bff067cc536d33b0d1a0b
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

Generik.LCAWDSY also known as:

SkyhighBehavesLike.Win32.BadFile.rc
McAfeeArtemis!A515DF16A5D7
MalwarebytesGeneric.Malware/Suspicious
K7AntiVirusTrojan ( 0057e7441 )
K7GWTrojan ( 0057e7441 )
ESET-NOD32a variant of Generik.LCAWDSY
AvastWin32:Trojan-gen
IkarusTrojan.SuspectCRC
VaristW32/SuspPack.BP.gen!Eldorado
Antiy-AVLHackTool[VirTool]/Win32.Obfuscator
XcitiumMalware@#930zzdr2fkdf
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.qN0@a8MAEwni
RisingTrojan.Generic@AI.100 (RDML:3qy48btKZ/pSvY/aF5oM/g)
FortinetW32/BHO.AA
AVGWin32:Trojan-gen
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Generik.LCAWDSY?

Generik.LCAWDSY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment