Malware

How to remove “Generik.SISWWN”?

Malware Removal

The Generik.SISWWN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.SISWWN virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Generik.SISWWN?


File Info:

name: 55D908F7CCB50AD0008F.mlw
path: /opt/CAPEv2/storage/binaries/7143030c5170af715a248abc927fed3ca72f39ffab7f5b71bc2711a451855dc4
crc32: 0AA72356
md5: 55d908f7ccb50ad0008fe7c7d0ea89a6
sha1: e3436ed47b58adede83774f721eb10ad68880438
sha256: 7143030c5170af715a248abc927fed3ca72f39ffab7f5b71bc2711a451855dc4
sha512: 5bc99362c7573c80527d99a352e6a953b3cd7493879d85630fb14a176f14708a0752d35861bc76bc2a9913105b984bc94d63ed1737f5e508dd3f92d0edd63a9b
ssdeep: 24576:0NA3R5drX/WfnIH57VKcGyqdL1Eg4s78cwRLCPWz5HrYgrED66VxSAC+IMMw:V5OfnIHzKeq5dELoWzJ6D66VxaTw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134752342FAE284B2E57305350A24AB6675BD7D303F248E2FB3CC5D6ED934191B2247A7
sha3_384: 75bcb07cbbd57b0af097fd0ba73e7a96f3e395ac8141f01f870ba8fd77fffd0c2a5d534ea9276507a817665207ec9cd5
ep_bytes: e85a040000e98efeffff3b0dc8a14300
timestamp: 2019-04-27 20:03:27

Version Info:

0: [No Data]

Generik.SISWWN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.BAT.Crypter.tqa8
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.ScriptKD.5499
McAfeeArtemis!55D908F7CCB5
CylanceUnsafe
VIPRETrojan.ScriptKD.5499
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.ScriptKD.5499
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7ccb50
ArcabitTrojan.ScriptKD.D157B
CyrenW32/S-8ed38c1a!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.SISWWN
Paloaltogeneric.ml
ClamAVWin.Packed.njRAT-9375380-0
KasperskyUDS:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/RarMal.adb0397b
CynetMalicious (score: 100)
Ad-AwareTrojan.ScriptKD.5499
EmsisoftTrojan.ScriptKD.5499 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.55d908f7ccb50ad0
SophosMal/RarMal-E
APEXMalicious
AviraTR/Patched.Gen
MicrosoftTrojan:Win32/Zpevdo.B
GDataZum.Rastarby.4
GoogleDetected
ALYacZum.Rastarby.4
MAXmalware (ai score=88)
VBA32Trojan.Agent
PandaTrj/CI.A
TencentWin32.Trojan.Agent.Jqil
FortinetRiskware/Bladabindi
AVGFileRepMalware [Trj]
AvastFileRepMalware [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.SISWWN?

Generik.SISWWN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment