Malware

Generik.CYTNMYH (file analysis)

Malware Removal

The Generik.CYTNMYH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CYTNMYH virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generik.CYTNMYH?


File Info:

name: 2610EBDFC70D1D2FA290.mlw
path: /opt/CAPEv2/storage/binaries/82a5c64d61174c170935d4a8f9b54a5e23c18667b100f3fa4f6b7714e37a0bf2
crc32: C0C84E97
md5: 2610ebdfc70d1d2fa29058886c97e6bd
sha1: 31b6a97fe957c765103fdac889064811f3c42bf9
sha256: 82a5c64d61174c170935d4a8f9b54a5e23c18667b100f3fa4f6b7714e37a0bf2
sha512: 1fb30e32b94ff2259b8ab8e6dce8dd639be7bbedb86c10d4393f9bbdb5575a67ee640304b77d927912d4b53ecf98e037395a491007ee3a1401ad8e5d5de287b0
ssdeep: 12288:ZKjMB76/3r4a58bXRi873L1vZXZfOvVU:MoB76j4a5K55Ay
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165B46D22B2E04537D26316789D1B87ACAC36BE103D2998862BF56C0D9F3D7C1756B2D3
sha3_384: 7b33d0994498408d6c935d0e2036d24e7d7b8b88be77c25623258b33a4cd7c56d39fa68eae59044e522ed6f41699b56d
ep_bytes: 558bec83c4f0b83cd04500e8d08afaff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: 嘉兴学院南湖学院[野球小子]
FileDescription: Windows文件监视器 V1.0
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: 何钱伟
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Generik.CYTNMYH also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.kZcP
MicroWorld-eScanTrojan.GenericKD.44033005
ALYacTrojan.GenericKD.44033005
CylanceUnsafe
SangforTrojan.Win32.CYTNMYH.ed
Cybereasonmalicious.fc70d1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.CYTNMYH
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.44033005
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.44033005
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.2610ebdfc70d1d2f
EmsisoftTrojan.GenericKD.44033005 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.44033005
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.220F6A4
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!2610EBDFC70D
TrendMicro-HouseCallTROJ_GEN.R002H0CIG21
IkarusTrojan.Win32.PolyCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Generik.CYTNMYH?

Generik.CYTNMYH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment