Malware

Generik.BEDOIST removal instruction

Malware Removal

The Generik.BEDOIST is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BEDOIST virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Generik.BEDOIST?


File Info:

name: D22004C427AB847104CF.mlw
path: /opt/CAPEv2/storage/binaries/3a5aeb64d385a892dd9a5e5b6c309ef2f642fe3b667fbe713581a982dddd480d
crc32: 380C982B
md5: d22004c427ab847104cf3f0309f8336d
sha1: 44ed2de8c655945fc870115cad514b58df3181a4
sha256: 3a5aeb64d385a892dd9a5e5b6c309ef2f642fe3b667fbe713581a982dddd480d
sha512: 03bbae30005dbf806fd00adab7273db8a65266cbabec79db1cc6bd2eb73e8b065dab823ac090b43a2d5e2b03cfcf5e8dd6d69af69c943c46687cd8fb266f004c
ssdeep: 1536:/lZ1PNq9uCUOFVSiHdq+sxne2FPo1065sPMgurHdCOSdBXaQ74p:/r1Pg9uCRFRzsxeuPo10JOSdB4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9936B227AE0C071E8E3217449FCA6625A3E797247758CC3379413EE9E703D19AB6363
sha3_384: a7f751f7341b2b85d1b6dffbf4be93a8c95a2dc55b009b24706b151954169ec9da80c21173cd71588c432c2cb996d297
ep_bytes: e82d180000e990feffffcccccccccc8b
timestamp: 2015-03-01 05:24:01

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Visual Studio Tools for Office Solution Installer
FileVersion: 10.0.60301.0 built by: VSTO_Rel
InternalName: VSTOInstaller.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: VSTOInstaller.exe
ProductName: Microsoft® Visual Studio® 2010
ProductVersion: 10.0.60301.0
Translation: 0x0409 0x04b0

Generik.BEDOIST also known as:

LionicWorm.Win32.AutoRun.o!c
DrWebWin32.HLLW.Autoruner.547
MicroWorld-eScanTrojan.GenericKD.38098662
FireEyeTrojan.GenericKD.38098662
McAfeeArtemis!D22004C427AB
ZillyaWorm.AutoRun.Win32.11523
K7AntiVirusRiskware ( 0040eff71 )
AlibabaWorm:Win32/AutoRun.3927a23b
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.427ab8
BitDefenderThetaAI:Packer.A86BECAD1C
ESET-NOD32a variant of Generik.BEDOIST
ClamAVWin.Worm.Vindor-9886047-0
BitDefenderTrojan.GenericKD.38098662
AvastWin32:VB-FBX
TencentWin32.Worm.Autorun.Wnvk
Ad-AwareTrojan.GenericKD.38098662
TrendMicroWORM_AUTORUN.BGA
McAfee-GW-EditionVindor-FTWO!5C5B1510A9DE
EmsisoftTrojan.GenericKD.47365936 (B)
MaxSecureTrojan.Malware.121218.susgen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKD.38098662
ALYacTrojan.GenericKD.47365936
MAXmalware (ai score=88)
VBA32Worm.AutoRun
MalwarebytesMalware.AI.3696146603
TrendMicro-HouseCallWORM_AUTORUN.BGA
RisingWorm.VB!1.DA41 (CLASSIC)
YandexTrojan.GenAsa!g8z8LT30jj4
IkarusTrojan.Dropper
FortinetW32/Agent.3B19!tr
AVGWin32:VB-FBX

How to remove Generik.BEDOIST?

Generik.BEDOIST removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment