Malware

Should I remove “Generik.CYWJPBS”?

Malware Removal

The Generik.CYWJPBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CYWJPBS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.CYWJPBS?


File Info:

crc32: FAA09630
md5: a96067cac28b1f5c3de4e1b6c7d0a402
name: A96067CAC28B1F5C3DE4E1B6C7D0A402.mlw
sha1: 51c65c8ece4bfd5c7d1b09105440f3f02d3b14ca
sha256: 79e70809a85e291f9da3d391131208ce7645dd512eb6bb71811154b43da23222
sha512: 1627058a9a884965bce4ece1ccf03c24a849cd79fe883c923ae2eb56c8e0bbb730cf823e550c080685af1f906a38f2847a65dc8ed236181d97eee9ddcfc3f96e
ssdeep: 6144:SqjIxGscXRNClwLJwAEZgVWnjNBjKTkst:jDduKmLyr
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright sociologist
FileVersion: 54.58.7.21
CompanyName: zombic
LegalTrademarks: dehumidify
Comments: survivor
ProductName: raw water
FileDescription: zombic
Translation: 0x0409 0x04e4

Generik.CYWJPBS also known as:

MicroWorld-eScanZum.Androm.1
FireEyeGeneric.mg.a96067cac28b1f5c
CylanceUnsafe
AegisLabTrojan.Win32.Androm.m!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderZum.Androm.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ac28b1
CyrenW32/Injector.AET.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Injector.27a06c1c
EmsisoftZum.Androm.1 (B)
F-SecureTrojan.TR/Injector.gztla
DrWebTrojan.Inject4.7268
TrendMicroBackdoor.Win32.ANDROM.THBAHBA
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
AviraTR/Injector.kvtba
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Injects
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Injector.SS!MTB
GridinsoftTrojan.Win32.Downloader.sa
ArcabitZum.Androm.1
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataWin32.Backdoor.Remcos.9LEOBE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Androm.R366720
McAfeeRDN/Generic BackDoor
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ZonerTrojan.Win32.104805
ESET-NOD32a variant of Generik.CYWJPBS
TrendMicro-HouseCallBackdoor.Win32.ANDROM.THBAHBA
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.EONL!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.Androm.HyoDWdsA

How to remove Generik.CYWJPBS?

Generik.CYWJPBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment