Malware

Generik.LXZKPKY (file analysis)

Malware Removal

The Generik.LXZKPKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LXZKPKY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs

How to determine Generik.LXZKPKY?


File Info:

crc32: 503D21C5
md5: ad6798822a09886c8459e4d7b9e298a3
name: AD6798822A09886C8459E4D7B9E298A3.mlw
sha1: 7ff4cfe2ae808060978c17bf664145f6018acdb4
sha256: c86a2c5702c2cb17b5d118ef377a4020a522b5967fd2e3494804f807789c74ee
sha512: 495c2ce9f957ec2337b5d1584685b37aec874a5b2b6b192de393915aebc5012f5d7ae0eafdcaa49dd17be0c10ccd1f04db946615ef6523125987d959f0155400
ssdeep: 768:DSggp7N7DR0jdI8aGbAf6uUK9Pjky+zABje2n92n0t9/xr:DY9j0Ozuc9JJBje2n92nI/xr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2008
InternalName: xv003
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: xv003
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: xv003
OriginalFilename: xv003.EXE
Translation: 0x0c07 0x04e4

Generik.LXZKPKY also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealRansom.Crowti.A6
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LXZKPKY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Ekstak.bvlx
NANO-AntivirusTrojan.Win32.Ekstak.evocgj
TencentWin32.Trojan.Ekstak.Lorn
SophosMal/Generic-S
ComodoMalware@#1lsy8rj5gy4gu
BitDefenderThetaGen:NN.ZexaF.34142.dq0@a8XpTozb
VIPRELooksLike.Win32.Crowti.b (v)
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ad6798822a09886c
JiangminTrojan.Ekstak.scp
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Tiggre!rfn
Acronissuspicious
McAfeeArtemis!AD6798822A09
MAXmalware (ai score=99)
VBA32Heur.Malware-Cryptor.Hlux
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
IkarusTrojan.SuspectCRC
FortinetW32/Ekstak.BVLX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.LXZKPKY?

Generik.LXZKPKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment