Malware

About “Generik.DHFGGCO” infection

Malware Removal

The Generik.DHFGGCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DHFGGCO virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generik.DHFGGCO?


File Info:

name: 3EFABDC26757DDFE499D.mlw
path: /opt/CAPEv2/storage/binaries/18cc92746f84939db668272114a8b9f45fcdff320e24e98e5e645022c81ee7ee
crc32: B778CEB7
md5: 3efabdc26757ddfe499d0ba0a40ff657
sha1: d7713c2641bc51bcabc8555be5c2fc29ad7a4a6c
sha256: 18cc92746f84939db668272114a8b9f45fcdff320e24e98e5e645022c81ee7ee
sha512: 9168d385fa376921c84c2b47f148681c8eb2e2da3bea3036925f2b2e40634bbe9eb146236972be10ba4a5a4b4d02950aed97575a7122c6c100725fbe27d5bde8
ssdeep: 384:hy73nutZBSh5nLgBPddQH/NMsNozwCpftNsGc9Ov50lzTDQFUC:k6ZBSh5nWLQF/NwwCiS50BQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A231A992A8A3552E0CA00385801D52A60656F4011FFCF93EDD667FBDE8F6F52808AF3
sha3_384: a98ecfdb077aff70b9242fd848528e6258e12f033d40fb586f8c754724457e7851a18361c7e1a8de53766eacb8984259
ep_bytes: 00000000000000000000000000000000
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

Generik.DHFGGCO also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Agentb.X!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.ECLZ
ClamAVWin.Malware.Eclz-9953021-0
FireEyeGeneric.mg.3efabdc26757ddfe
McAfeeGenericRXKJ-LP!3EFABDC26757
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPRETrojan.Agent.ECLZ
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.0de56057
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/S-9d209b27!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DHFGGCO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.bxov
BitDefenderTrojan.Agent.ECLZ
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Agent.zbj
EmsisoftTrojan.Agent.ECLZ (B)
TrendMicroTROJ_GEN.R002C0PAU23
McAfee-GW-EditionBehavesLike.Win32.Generic.pz
Trapminesuspicious.low.ml.score
SophosML/PE-A
IkarusTrojan.Crypt
GDataTrojan.Agent.ECLZ
JiangminTrojan.Multi.jtl
AviraTR/Crypt.ULPM.Gen
ArcabitTrojan.Agent.ECLZ
ViRobotTrojan.Win32.Z.Eclz.45568.AA
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Worm/Win32.Agent.R304664
ALYacTrojan.Agent.ECLZ
MAXmalware (ai score=83)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PAU23
RisingTrojan.Generic@AI.99 (RDMK:MMduNcDfyQIz8edc6fEMHg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.26757d
PandaTrj/Chgt.AD

How to remove Generik.DHFGGCO?

Generik.DHFGGCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment