Malware

Generik.MUVEWYW removal instruction

Malware Removal

The Generik.MUVEWYW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MUVEWYW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Generik.MUVEWYW?


File Info:

name: 0C01FD4DB842131E0576.mlw
path: /opt/CAPEv2/storage/binaries/b1015f1a8211328580c6d6e7590065aa5e66be1feeb9aec254d1a3f6a9889e75
crc32: 4B039A0D
md5: 0c01fd4db842131e0576a35ad41bd076
sha1: 2c18191f08f627e0ec0ebefcb7ea7633d5022d5c
sha256: b1015f1a8211328580c6d6e7590065aa5e66be1feeb9aec254d1a3f6a9889e75
sha512: 049e42e71fcdfd941093f8a70d29c2fe3e700be2a7f3a533813e237f5447a7490918721b1d62b01670ad683a889cff8553ca56106c39dcf43d0dc7624c5c1639
ssdeep: 12288:+GlaKpQeGkt5PQ+pY8aMO39Jz5SyspS9eFI:nlpp5GsBpraB39JNS1/I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127B4D09174ACD1D3E5AA0CB268ABF23130E439DED1CA514F3799B76A60B2392405F73D
sha3_384: 224e7dbd0efce4a242e582262458a7de982d594c8f7578e37d4375b216c188a001820a2002ccea061d37fd753a2b8d08
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Generik.MUVEWYW also known as:

LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.GenericKDZ.81412
FireEyeDropped:Trojan.GenericKDZ.81412
McAfeeArtemis!0C01FD4DB842
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Tnega.0fb55f75
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.db8421
CyrenW32/Injector.AQQ.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Generik.MUVEWYW
TrendMicro-HouseCallTROJ_GEN.F0D1C00L721
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderDropped:Trojan.GenericKDZ.81412
AvastWin32:PWSX-gen [Trj]
Ad-AwareDropped:Trojan.GenericKDZ.81412
SophosMal/Generic-S
DrWebTrojan.DownLoader44.12213
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
SentinelOneStatic AI – Suspicious PE
EmsisoftDropped:Trojan.GenericKDZ.81412 (B)
APEXMalicious
MAXmalware (ai score=80)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Win.514892
GDataWin32.Trojan-Stealer.FormBook.VFVAM8
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Lokibot.R443000
VBA32TrojanSpy.Noon
ALYacDropped:Trojan.GenericKDZ.81412
MalwarebytesMalware.AI.2951221103
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.AQQ!tr
WebrootW32.Trojan.Dropper
AVGWin32:PWSX-gen [Trj]

How to remove Generik.MUVEWYW?

Generik.MUVEWYW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment