Malware

Generic.SysHijack.226C51BA removal

Malware Removal

The Generic.SysHijack.226C51BA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.SysHijack.226C51BA virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.SysHijack.226C51BA?


File Info:

name: ACE89709B1CA5DB8462D.mlw
path: /opt/CAPEv2/storage/binaries/42358abb26dd85607ff009a8cc3d2a02dbbd6647e74c50d3c4cfc80ee85e3d1d
crc32: 7E9B5A55
md5: ace89709b1ca5db8462d238712ab2ee7
sha1: 4a8d802b358339b49909e6550f76e6e329854ec5
sha256: 42358abb26dd85607ff009a8cc3d2a02dbbd6647e74c50d3c4cfc80ee85e3d1d
sha512: aee3e250ff017d5c52b06bb68a144df5b9031bb471e7df310b7ac6834d20857eda642e003552b32cde4fb932754105499d39392400c88220ab9cb9984b61e3eb
ssdeep: 768:GT4wO+GkS0JARrVibDdPNfLxdGGVkT/bmyf05gq0:aOxrVSfW3s5Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0E26C13AF8A58F6F4916130004BA773663BE8A0037C66FB5E90DCBA58721B1D97534F
sha3_384: c1745b00a949de26dd7ee50f86ff679a0b608d022e0705fcf50aec12f977310ad77ffeb5a3cd2da97267517dc9f6f8ff
ep_bytes: 558bec6aff682862400068a056400064
timestamp: 2009-06-27 11:25:33

Version Info:

CompanyName: Beijing Rising Information Technology Co., Ltd.
FileDescription: RavCopy Module
FileVersion: 21.0.0.17
InternalName: Beijing Rising Information Technology Co., Ltd.
LegalCopyright: Copyright(C) 2008-2009 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.
OriginalFilename: ravcopy.exe
ProductName: Rising AntiVirus 2009
ProductVersion: 21.00
SpecialBuild: 668531044687500
Translation: 0x0409 0x04b0

Generic.SysHijack.226C51BA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.lh6m
MicroWorld-eScanGeneric.SysHijack.226C51BA
ClamAVWin.Downloader.119580-1
FireEyeGeneric.mg.ace89709b1ca5db8
CAT-QuickHealBackdoor.Darkshell
McAfeeBackDoor-DKA.j
Cylanceunsafe
ZillyaBackdoor.Yoddos.Win32.1017
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Yoddos.87d9bf96
K7GWTrojan ( 002443921 )
K7AntiVirusTrojan ( 002443921 )
BaiduWin32.Backdoor.Agent.es
VirITBackdoor.Win32.Httpbot.XL
CyrenW32/QQhelper.C.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.NWM
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Yoddos.an
BitDefenderGeneric.SysHijack.226C51BA
NANO-AntivirusTrojan.Win32.Scar.bjumn
SUPERAntiSpywareTrojan.Agent/Gen-Yoddos
AvastWin32:BackdoorX-gen [Trj]
TencentTrojan.TenThief.DNFDownloader.ti
EmsisoftGeneric.SysHijack.226C51BA (B)
F-SecureTrojan:W32/SystemHijack.gen!A
DrWebBackDoor.Darkshell.246
VIPREGeneric.SysHijack.226C51BA
TrendMicroBKDR_YODDOS.SM
McAfee-GW-EditionBehavesLike.Win32.Downloader.nm
Trapminemalicious.high.ml.score
SophosMal/Agent-IJ
Ikaruspossible-Threat.Tool
GDataGeneric.SysHijack.226C51BA
JiangminTrojanDropper.Agent.ygl
WebrootW32.Rogue.Gen
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Yoddos.an
XcitiumTrojWare.Win32.TrojanDownloader.Small.DG@1d0x87
ArcabitGeneric.SysHijack.226C51BA
ViRobotTrojan.Win32.DDos-Agent.31744.C
ZoneAlarmBackdoor.Win32.Yoddos.an
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.CSon.R1800
Acronissuspicious
BitDefenderThetaAI:Packer.E050112E1F
ALYacGeneric.SysHijack.226C51BA
MAXmalware (ai score=86)
VBA32SScope.Trojan-Inject.Agent.01084
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/P2PWorm.QD.worm
TrendMicro-HouseCallBKDR_YODDOS.SM
RisingBackdoor.UUBeat!1.6486 (CLASSIC)
YandexTrojan.GenAsa!lC22aWAcZ/E
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1683237.susgen
FortinetW32/Agent.AWE!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generic.SysHijack.226C51BA?

Generic.SysHijack.226C51BA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment