Malware

About “Generik.BVQQOAH” infection

Malware Removal

The Generik.BVQQOAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BVQQOAH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generik.BVQQOAH?


File Info:

name: 7165CC6D9AA75D50DB7D.mlw
path: /opt/CAPEv2/storage/binaries/ca143d7cbb28bb6a66d0b125347d4a7bbd8433ad9e2865a9d27d1de3f687aa65
crc32: A57247AD
md5: 7165cc6d9aa75d50db7d9d58bc5a1017
sha1: 25787e2a235f4d4e5e810ae6b9e48c61f47d2728
sha256: ca143d7cbb28bb6a66d0b125347d4a7bbd8433ad9e2865a9d27d1de3f687aa65
sha512: 16c112bf15f9c9d19aee033b3ddf9f56ccde61980a68f4d9c3c6f428739ae99ba6be4f4735f9997e2a402b46479a21b5e43d7fd0d0e0f6a10a06b44169ed0f46
ssdeep: 6144:PYa6Kf1mSIXSvk+Pk9AXQPhSUHJmyp2xaAT2I7jQS8LC:PYMtzIikKXQJSUHX2gAN7jQS8LC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1365412145FE5C477C4B20A731E3E1257AEFAEC0510E9AB5B27200F5D7E631A1982E3B6
sha3_384: f9db561485a5833e2fb995bb23f6914968fa264665e296f0a2f5a5dd1234ea20a0443738f4615aab1726f6de1b8e4c39
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

CompanyName: epifaunal
FileDescription: regressors
FileVersion: 40.74.41.87
LegalCopyright: Copyright snow-winged
ProductName: 40.74.41.87
Translation: 0x0409 0x04b0

Generik.BVQQOAH also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blakken.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68703323
SkyhighBehavesLike.Win32.Generic.dc
ALYacTrojan.GenericKD.68703323
Cylanceunsafe
VIPRETrojan.GenericKD.68703323
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005aafe71 )
AlibabaTrojan:Win32/Strab.2235c96b
K7GWTrojan ( 005aa0261 )
Cybereasonmalicious.a235f4
VirITTrojan.Win32.Genus.SUH
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.BVQQOAH
ZonerTrojan.Win32.160262
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderTrojan.GenericKD.68703323
NANO-AntivirusTrojan.Win32.Strab.jyowxr
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan.Strab.Jcnw
EmsisoftTrojan.GenericKD.68703323 (B)
F-SecureTrojan.TR/AD.GenShell.cjsfl
DrWebTrojan.Siggen21.18443
TrendMicroTROJ_GEN.R03BC0DHI23
FireEyeGeneric.mg.7165cc6d9aa75d50
SophosTroj/Inject-JBY
IkarusTrojan.Win32.Injector
GoogleDetected
AviraTR/AD.GenShell.tixks
Antiy-AVLTrojan/Win32.Lokibot
MicrosoftTrojan:Win32/Leonem
XcitiumMalware@#28shp82ougf3q
ArcabitTrojan.Generic.D418545B
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
GDataTrojan.GenericKD.68703323
VaristW32/Ninjector.JO.gen!Eldorado
AhnLab-V3Trojan/Win.NSISInject.R587856
McAfeeArtemis!7165CC6D9AA7
MAXmalware (ai score=86)
VBA32Trojan.Strab
MalwarebytesTrojan.Injector
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DHI23
RisingTrojan.Strab!8.12D03 (TFE:5:HdCNxQybg6M)
YandexTrojan.Igent.b0FzTd.4
SentinelOneStatic AI – Malicious PE
FortinetNSIS/Agent.DCAC!tr
BitDefenderThetaGen:NN.ZedlaF.36744.fu4@aenkr8ei
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.BVQQOAH?

Generik.BVQQOAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment