Malware

Should I remove “Generik.DCYYTMQ”?

Malware Removal

The Generik.DCYYTMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DCYYTMQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.DCYYTMQ?


File Info:

crc32: 6A9FF42B
md5: 577a27a2f23604c453add94cb36bf8b8
name: 577A27A2F23604C453ADD94CB36BF8B8.mlw
sha1: 49bdc83acd851e28c2ec88c3fbf75b5b32a2e791
sha256: 68d86aa42984f3c90b87ea0435800d3f741086c63d52fa1fe957897c1ed624ff
sha512: 1ba2f1c0ddf9047df9bef380bc0b74fe58ce229ce37424a71824c34c64250d6fe82666ff95d57deae58739e94e67359b09079e5e91115a16801e631d8570064e
ssdeep: 98304:VKTs8swKzbXDPVyn3No3zWQG+QdKlyzTd3I9QOU0/Vq888zZQnrusgbMWc4RENQ:qsbbzn3oekm2OJ7yrJUXaBWh1Mj10A0
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.5
TranslationUsa: 0x0273 0x04d3

Generik.DCYYTMQ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKD.35930633
FireEyeGeneric.mg.577a27a2f23604c4
ALYacTrojan.AntiSandbox.GenericKD.35930633
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005757711 )
BitDefenderTrojan.AntiSandbox.GenericKD.35930633
K7GWTrojan ( 005757711 )
Cybereasonmalicious.acd851
BitDefenderThetaGen:NN.ZexaF.34700.@pKfayKZ18hG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Eb.bha
AlibabaTrojan:Win32/GoCloudnet.eba90802
TencentWin32.Trojan.Eb.Swbi
Ad-AwareTrojan.AntiSandbox.GenericKD.35930633
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/AD.GoCloudnet.llokg
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/AD.GoCloudnet.llokg
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.AntiSandbox.Generic.D2244209
ZoneAlarmTrojan.Win32.Eb.bha
GDataTrojan.AntiSandbox.GenericKD.35930633
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!577A27A2F236
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Generik.DCYYTMQ
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.443F.Malware.Gen

How to remove Generik.DCYYTMQ?

Generik.DCYYTMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment