Malware

Should I remove “Generik.BYSVKAO”?

Malware Removal

The Generik.BYSVKAO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BYSVKAO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.BYSVKAO?


File Info:

crc32: 49B3471D
md5: beb0af52d4ae28e35867f414b58565e3
name: upload_file
sha1: 9e7c60e25d14913704db9a8e082ccd799c8c423a
sha256: 33ee7efb2dbddfe1e5722a450613455d5584e777c4d0a92fbb3fe11faf28d8ab
sha512: 5b7f41359f915873f83a0f584e7f7ab635e2c05f30771856a5c45d3768750f08d1e562c3ea5e6891cf2c07c51d15c5815d270a5d2bfbbffb7a4932d903b4ab74
ssdeep: 3072:WrXmwZHVaEDYYeIguH6Vk39LzQx8YNidHSrEc9fEACG363bDdToIXtGgpeE4q6uS:w7YEDYYeIgu4k3JQfH92ToHrkwDpY2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: wGrep
FileVersion: 1.00
CompanyName: Preferred Organization
ProductName: wGrep
ProductVersion: 1.00
FileDescription: Key experts gather together to provide
OriginalFilename: wGrep.exe

Generik.BYSVKAO also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.34822096
Qihoo-360Win32/Trojan.436
McAfeeRDN/Emotet
MalwarebytesTrojan.MalPack.TRE
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.34822096
ArcabitTrojan.Generic.D21357D0
TrendMicroTrojanSpy.Win32.EMOTETCRYPT.USMANJJ20
CyrenW32/Injector.ADH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.BYSVKAO
TrendMicro-HouseCallTrojanSpy.Win32.EMOTETCRYPT.USMANJJ20
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.geks
APEXMalicious
RisingTrojan.Kryptik!1.C606 (CLASSIC)
Ad-AwareTrojan.GenericKD.34822096
EmsisoftTrojan.GenericKD.34822096 (B)
F-SecureTrojan.TR/AD.Emotet.ewn
DrWebTrojan.DownLoader35.3592
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
FireEyeTrojan.GenericKD.34822096
IkarusWin32.Outbreak
WebrootW32.Trojan.Gen
AviraTR/AD.Emotet.ewn
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
ZoneAlarmTrojan-Banker.Win32.Emotet.geks
GDataTrojan.GenericKD.34822096
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R353413
PandaTrj/Agent.PM
FortinetW32/Generik.BYSVKAO!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Generik.BYSVKAO?

Generik.BYSVKAO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment