Malware

What is “Generik.MPYWFCI”?

Malware Removal

The Generik.MPYWFCI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MPYWFCI virus can do?

  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.MPYWFCI?


File Info:

name: 3ECF4ADDBFDFA344B071.mlw
path: /opt/CAPEv2/storage/binaries/737d02a438389473a355c5a0c996b653ff7bab2a02cd850ac13740edd57af235
crc32: FAB01C70
md5: 3ecf4addbfdfa344b07197b48dab56aa
sha1: 576b5e3b312bf2d0f795d48779af60251545c8c5
sha256: 737d02a438389473a355c5a0c996b653ff7bab2a02cd850ac13740edd57af235
sha512: 8bd162fe657a96e2fa804eacfd66cd60c5f5e3f18bd37ac235d6a1f4caa0476f3cbfaf3d9fb4f351738ac4ec7fd7b5c49352b6562082c9a23f5cbc618ba3f973
ssdeep: 98304:wXgLbfCEZfyO9QO9sf2tuQGLTDZZ3m0K:wX6TCEZfyO9QO9S2tu/DZZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138068D12F391C437D16715389D0B87A4A536BE12AF2494C7BBE63F0DAF317C16A36286
sha3_384: 848ca654589bdcc3e07f6c136c28628eb7d0bb55331e011dc1ec7e63b3892006aad0bf2b62341f5ef7355812a3a883d3
ep_bytes: 558bec83c4f4b824370b10e89433f5ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Generik.MPYWFCI also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.70277366
FireEyeTrojan.GenericKD.70277366
SkyhighBehavesLike.Win32.Generic.wh
ALYacTrojan.GenericKD.70277366
SangforHacktool.Win32.Delfinject.Vnuh
K7AntiVirusRiskware ( 00584baa1 )
AlibabaVirTool:Win32/DelfInject.099989c0
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.b312bf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.MPYWFCI
APEXMalicious
CynetMalicious (score: 99)
BitDefenderTrojan.GenericKD.70277366
AvastWin32:Delf-BQR [Trj]
RisingHackTool.DelfInject!8.B26 (TFE:5:hfqNal61erP)
EmsisoftTrojan.GenericKD.70277366 (B)
F-SecureTrojan.TR/Delf.Inject.otikn
VIPRETrojan.GenericKD.70277366
TrendMicroTROJ_GEN.R03BC0DKE23
SophosMal/Generic-S
IkarusVirus.Win32.DelfInject
AviraTR/Delf.Inject.otikn
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftVirTool:Win32/DelfInject.gen!X
ArcabitTrojan.Generic.D43058F6
GDataTrojan.GenericKD.70277366
AhnLab-V3Trojan/Win.DelfInject.C5539592
McAfeeArtemis!3ECF4ADDBFDF
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DKE23
MaxSecureTrojan.Malware.219204483.susgen
FortinetW32/PossibleThreat
AVGWin32:Delf-BQR [Trj]
DeepInstinctMALICIOUS

How to remove Generik.MPYWFCI?

Generik.MPYWFCI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment