Malware

How to remove “Generik.LLVZUNZ”?

Malware Removal

The Generik.LLVZUNZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LLVZUNZ virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
gachimucci.000webhostapp.com

How to determine Generik.LLVZUNZ?


File Info:

crc32: DB5C2023
md5: 8db4ac8849f6b98868e08f494c3ebd97
name: crown_cheat.exe
sha1: f29b11ffd73cd2f40601af2bdab33467c2e66679
sha256: ba01fa831a0e07dcbd85098caad15f7247564357ad06ed67043af3f59271af3b
sha512: ca65f438fc042a914f2fe80f458ed1005dc99876ffe3ccb4503b4e62f796f94855457f608733705a8ec582c62bf12b8296a63afc8df6aca554546164af3ed4a4
ssdeep: 24576:sNA3R5drXa0ZPZU4RSUUEyU29L7VrBgmOFHCiX29yAa5aBNIX8:t5b5dVUEj2J79BgmYHO9yAaEB2M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.LLVZUNZ also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42868539
FireEyeGeneric.mg.8db4ac8849f6b988
CAT-QuickHealTrojan.Multi
Qihoo-360Generic/Backdoor.91b
McAfeeArtemis!8DB4AC8849F6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42868539
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (W)
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.LLVZUNZ
APEXMalicious
AvastWin32:Trojan-gen
GDataZum.Rastarby.3
KasperskyBackdoor.MSIL.Bladabindi.berm
AlibabaBackdoor:MSIL/Bladabindi.519a9e20
AegisLabTrojan.BAT.Crypter.tqa8
TencentMsil.Backdoor.Bladabindi.Eerk
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Bladabindi.sphhr
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
EmsisoftTrojan.GenericKD.42868539 (B)
IkarusTrojan-Dropper.SFX.Agent
AviraTR/AD.Bladabindi.sphhr
MAXmalware (ai score=81)
ArcabitZum.Rastarby.3
ZoneAlarmBackdoor.MSIL.Bladabindi.berm
MicrosoftBackdoor:MSIL/Bladabindi.AJ
Acronissuspicious
PandaTrj/CI.A
RisingTrojan.Pack-RAR!1.BB61 (CLASSIC)
AVGWin32:Trojan-gen
Cybereasonmalicious.849f6b
Paloaltogeneric.ml

How to remove Generik.LLVZUNZ?

Generik.LLVZUNZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment