Malware

Should I remove “Generik.DYOTNLI”?

Malware Removal

The Generik.DYOTNLI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DYOTNLI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generik.DYOTNLI?


File Info:

name: AD04E533B56E0801B016.mlw
path: /opt/CAPEv2/storage/binaries/1adf68c417f77fd3a482c6334a5f43a2185c568886634fa91fd561a67ad1a257
crc32: 81B03E20
md5: ad04e533b56e0801b01698e70d5c7b68
sha1: 0877f144bad6278c1db7ddfb8134f0ee4432a16e
sha256: 1adf68c417f77fd3a482c6334a5f43a2185c568886634fa91fd561a67ad1a257
sha512: 285d5d0c8811d245a2adbe7a75b0d39e0989ff51e9be5f25189928c279e18e2de84e5a004044116a12b7c2c8a58a152bc7a00489c0f26bb598fa6f0ce5c983da
ssdeep: 196608:aze6XTlYrKk/VSlP1v+7XOf+57TBVqqnDTR4:EeSTlNk/yPsre+zpTR4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D46612A3F484A43AF45D2B354173AC2CD4FBA769A406AD1552E0CC89FB72FC21D3652B
sha3_384: 5983a4da50c9562dc6e812d701e197cd79b48a6da1e103bf45a1a2397b06cb63d68a07d5cd528ef3da3ccc652ac613b8
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-10-12 11:15:57

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: 360 Total Security Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: 360 Total Security
ProductVersion: 0.0.0.1
Translation: 0x0000 0x04b0

Generik.DYOTNLI also known as:

BkavW32.Common.CA68CF8D
DrWebAdware.Downware.20520
MalwarebytesPUP.Optional.BundleInstaller
K7AntiVirusAdware ( 005ad2df1 )
K7GWAdware ( 005ad2df1 )
ESET-NOD32a variant of Generik.DYOTNLI
NANO-AntivirusRiskware.Win32.Adw.kkcfhq
KingsoftWin32.Troj.Unknown.a
GDataWin32.Trojan.Agent.2SGAJ4
IkarusTrojan.SuspectCRC
FortinetRiskware/MorganCatering
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Generik.DYOTNLI?

Generik.DYOTNLI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment