Malware

How to remove “Generik.LZFVUON”?

Malware Removal

The Generik.LZFVUON is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LZFVUON virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Generik.LZFVUON?


File Info:

name: E1B2AD38BD1C732BCB91.mlw
path: /opt/CAPEv2/storage/binaries/0888b07a59ce5296eb9823089ba6c7b82a8724fae1468448071083996c5b01f6
crc32: 722CE6ED
md5: e1b2ad38bd1c732bcb9126b5307bb716
sha1: 159d32e2afb8664c72704afa3a4d78ade61f3039
sha256: 0888b07a59ce5296eb9823089ba6c7b82a8724fae1468448071083996c5b01f6
sha512: f5b2d0b2b5ec82602fba7385bcbb95e57681db2b054725a7f932dbf0cd9164374b119acdc5bb2ffdfe851fe9a9a79835b31dbb881797f7e4e191a27349e5a48a
ssdeep: 6144:A5OkVU9JrhfbCVEB38nb369sG+Kz3QUDTSnsR:AMHVLJI2h3R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C54E02358826EABC0B651F38DC7382CD93C6E6551380B2B37EDD9272966315F73781A
sha3_384: 9e6eec2339b8cdc225563359582f5a36f596558565f48e3a7aa42fa5b52f2260eaec6f116d7ead4ccd79b092797411e6
ep_bytes: 558bec83ec20ff75f052525150ff75e4
timestamp: 2004-10-01 16:40:04

Version Info:

0: [No Data]

Generik.LZFVUON also known as:

LionicHacktool.Win32.Krap.loUd
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.538
CynetMalicious (score: 100)
FireEyeGeneric.mg.e1b2ad38bd1c732b
ALYacGen:Variant.Razy.45939
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.101535
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/FakeAV.d3754342
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.7B7A5C8B1F
VirITTrojan.Win32.Panda.US
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LZFVUON
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1281
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.45939
NANO-AntivirusTrojan.Win32.Zbot.iiinf
MicroWorld-eScanGen:Variant.Razy.45939
AvastWin32:MalOb-IJ [Cryp]
TencentMalware.Win32.Gencirc.114be6c2
Ad-AwareGen:Variant.Razy.45939
EmsisoftGen:Variant.Razy.45939 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
VIPREPacked.Win32.Zbot.gen.y.8 (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Spyeye.dm
SophosML/PE-A + Mal/FakeAV-BW
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Razy.45939
JiangminTrojanSpy.Zbot.aqhv
AviraTR/Crypt.XPACK.Gen8
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Razy.DB373
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot.gen!Y
McAfeePWS-Spyeye.e
VBA32Trojan.Zeus.EA.0999
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!PLxKtqY91Zk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/SpyEye.SK!tr
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/Sinowal.XHV

How to remove Generik.LZFVUON?

Generik.LZFVUON removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment