Malware

Generik.LFCZPLX removal

Malware Removal

The Generik.LFCZPLX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LFCZPLX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Generik.LFCZPLX?


File Info:

name: F9436BA7253F45EA012D.mlw
path: /opt/CAPEv2/storage/binaries/4a02cf44a84220b61d00e09bb3875c00804632c5e4b7e49622a375ef7ee3b138
crc32: BE197820
md5: f9436ba7253f45ea012d1247c05a42db
sha1: 9a211953dea7de63f9d886aa8622335f70372408
sha256: 4a02cf44a84220b61d00e09bb3875c00804632c5e4b7e49622a375ef7ee3b138
sha512: dc127f97915aa6061867d3bec82dbfa0c4769a4217112e5fc5a0c2bf8c559443477239933e0e830d343a996a456890e1b9b428c28acf557f601eab896fd73ec3
ssdeep: 24576:R3oCTWeZPEfxnW9yFdNM+lu8n5bpGLIe1hdp1YdGrksfC3fTItkgbVU+n0Stfsr6:R3XTWsOBDNQ2iselXOfTITJR0nrtFPO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109852312B9C0D0B2D036143518F986B5643CBC315B2A96CFA3A57E795F302E42B7A9DF
sha3_384: b3e4a92b7db4c13e09cd10c57f9b1f7fc28f0a61986e7bcbc271ce1d27bb21e27e2c886887d7befbaeb615062c9538a3
ep_bytes: e836050000e98efeffffcccccc575653
timestamp: 2018-09-04 14:43:33

Version Info:

0: [No Data]

Generik.LFCZPLX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Crypren.tpW3
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.3428
MicroWorld-eScanTrojan.GenericKD.47281292
FireEyeGeneric.mg.f9436ba7253f45ea
ALYacTrojan.GenericKD.47281292
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Occamy.f2042cc8
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/S-f857af78!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LFCZPLX
TrendMicro-HouseCallTROJ_GEN.R02DC0DL921
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.47281292
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47281292
SophosML/PE-A
ComodoWorm.Win32.Bflient.~AD2@3d18gh
TrendMicroTROJ_GEN.R02DC0DL921
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.47281292 (B)
IkarusTrojan.Win32.Ymacco
GDataWin32.Trojan.PSE.6J8F2R
MaxSecureWin.MxResIcn.Heur.Gen
AviraHEUR/AGEN.1134395
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.AA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R342010
McAfeeArtemis!F9436BA7253F
VBA32Trojan.BtcMine
MalwarebytesTrojan.Downloader
APEXMalicious
MAXmalware (ai score=89)
eGambitUnsafe.AI_Score_99%
FortinetW32/GenericKD.4266!tr
AVGWin32:Malware-gen
Cybereasonmalicious.7253f4
PandaTrj/CI.A

How to remove Generik.LFCZPLX?

Generik.LFCZPLX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment