Malware

What is “Generik.BYGLCNI”?

Malware Removal

The Generik.BYGLCNI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BYGLCNI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Generik.BYGLCNI?


File Info:

name: D5F1E38ABA988679E0CA.mlw
path: /opt/CAPEv2/storage/binaries/81cd15c231e6f03c85845f728e02c024238f8dabae1f222584a11e82b56ce9d7
crc32: 4B47DE3D
md5: d5f1e38aba988679e0ca4e9210166b4e
sha1: fb9e04e44639721979b2696e7dcc0647d35e6c9b
sha256: 81cd15c231e6f03c85845f728e02c024238f8dabae1f222584a11e82b56ce9d7
sha512: 191478f99542d4201832ee4b77b9ac12794b6f7b3d0d0fd1c3d268bb60222dedb3d42fed8f946428ff99cd783a0b0a87d4b92224eacea634dd7e8d568ed427b8
ssdeep: 12288:MBlGIVioZI9X+JYbD2nVzHRxSDD/ITRwwgx5zw:M7VbZI9XbQHR4AY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109F49E127690A8F1C15E3D71492ADE64D1FDBC218E68177766D03ABDBE31391BD2C20E
sha3_384: 3050cd48356ba9fb2b3854dfb5d731128da5a198814fabd4adc559930ae95d601f1e97c0bd06072258fdba1d9ab8fff4
ep_bytes: e872600000e978feffff6a0c68000744
timestamp: 2022-03-23 06:19:32

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft(R) Windows(R) Operating System
FileVersion: 1.2.10.2798
InternalName: LOAD
LegalCopyright: 版权所有 (C) 1986
OriginalFilename: LOAD.EXE
ProductName: 应用程序
ProductVersion: 1.2.10.2798
Translation: 0x0804 0x04b0

Generik.BYGLCNI also known as:

LionicTrojan.Win32.PcClient.m!c
MicroWorld-eScanTrojan.GenericKD.39846768
FireEyeTrojan.GenericKD.39846768
ALYacTrojan.GenericKD.39846768
AlibabaTrojan:Win32/BurHon.09dfdec6
Cybereasonmalicious.446397
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.BYGLCNI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.BurHon.gen
BitDefenderTrojan.GenericKD.39846768
AvastWin32:Malware-gen
TencentWin32.Trojan.Burhon.Wtwz
Ad-AwareTrojan.GenericKD.39846768
SophosMal/Generic-S
TrendMicroTROJ_GEN.R03BC0WFO22
McAfee-GW-EditionGenericRXTK-WK!D5F1E38ABA98
EmsisoftMalware.Generic.CN1 (A)
GDataTrojan.GenericKD.39846768
AviraTR/Redcap.zivzr
ArcabitTrojan.Generic.D2600370
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeGenericRXTK-WK!D5F1E38ABA98
MAXmalware (ai score=87)
TrendMicro-HouseCallTROJ_GEN.R03BC0WFO22
RisingBackdoor.PcClient!8.119 (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34742.Tu0@a8enPfhj
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.BYGLCNI?

Generik.BYGLCNI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment