Malware

Generik.BAZHMJF removal instruction

Malware Removal

The Generik.BAZHMJF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BAZHMJF virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Formbook malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.BAZHMJF?


File Info:

name: 0E577D1C83FD86921425.mlw
path: /opt/CAPEv2/storage/binaries/e7822ff092bf47fa0a7911e32d9f2433a9946bc7b5bfd4dc9a110180960f40a0
crc32: 570D550A
md5: 0e577d1c83fd86921425c76f1b77665a
sha1: 24cefbf94c92e2d1b36dae070c79d5e460d01b04
sha256: e7822ff092bf47fa0a7911e32d9f2433a9946bc7b5bfd4dc9a110180960f40a0
sha512: 3b74153a376e393070aa723633ca0ab8ee5b31af0e37af75eb6d5098a498f2078dec445086d5e3fadaf9e105f729e044e9c510cb176a1b23083d1d865c1d6417
ssdeep: 3072:hOpq32GadHlFgM1izIWQ5d3Dt+xKrfpL9nX/01H3ue:hrSb6M1iDQ5dzt+xefp9nE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119F39E32DA42C031E2B251F5B26D1B7B893D0D34335561AAE3E61AE16EF05E6F42931F
sha3_384: 71a4cc304ed4d86ba94f8053ba2d0bc7ebdf49e9c5dd8ed6de6f23a86b94b0ad26c4e6b7c5d2a19fd72abc5d27d463c6
ep_bytes: 558bec83ec64e875c7ffff8be55dc3e8
timestamp: 2014-08-22 03:05:53

Version Info:

0: [No Data]

Generik.BAZHMJF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Noon.4!c
ElasticWindows.Trojan.Formbook
DrWebTrojan.Siggen9.48175
MicroWorld-eScanGen:Variant.Zusy.299012
FireEyeGeneric.mg.0e577d1c83fd8692
McAfeeGenericRXLS-VV!0E577D1C83FD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Formbook.Win32.2362
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00536d121 )
AlibabaTrojan:Win32/Formbook.ce36ab25
K7GWTrojan ( 00536d121 )
Cybereasonmalicious.c83fd8
BitDefenderThetaAI:Packer.2C60844F1E
CyrenW32/ABRisk.PJWQ-5035
SymantecTrojan.Formbook
ESET-NOD32a variant of Generik.BAZHMJF
APEXMalicious
ClamAVWin.Malware.Formbook-9951648-0
KasperskyUDS:Trojan.Win64.GenericML.xnet
BitDefenderGen:Variant.Zusy.299012
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Formbook-B [Trj]
TencentWin32.Trojan.Crypt.Tsmw
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPREGen:Variant.Zusy.299012
TrendMicroTrojan.Win32.FORMBOOK.YXDG3Z
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.299012 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10Z9ZNT
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Formbook.A
ArcabitTrojan.Zusy.D49004
ViRobotTrojan.Win.Z.Formbook.163328
ZoneAlarmUDS:Trojan.Win64.GenericML.xnet
MicrosoftTrojan:Win32/Formbook!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Formbook.X2185
Acronissuspicious
ALYacGen:Variant.Zusy.299012
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.FORMBOOK.YXDG3Z
RisingStealer.Fareit!8.170 (TFE:2:TXFxpikg56)
YandexTrojan.Agent!ud1ELRf6uMQ
IkarusTrojan-Spy.FormBook
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.AYEB!tr
AVGWin32:Formbook-B [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.BAZHMJF?

Generik.BAZHMJF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment