Malware

Generik.EMYTNQT removal

Malware Removal

The Generik.EMYTNQT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EMYTNQT virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.EMYTNQT?


File Info:

name: E8AA1D90BC232631FA23.mlw
path: /opt/CAPEv2/storage/binaries/12b5b07d1486d5fc1f7fc4a2e447197aa4ab9168dec6cc1dbab19cad31bc887e
crc32: 88468BC0
md5: e8aa1d90bc232631fa238a79e5355a31
sha1: 9902e6ecfb35644ea6b466faf2f4c1aecfa47686
sha256: 12b5b07d1486d5fc1f7fc4a2e447197aa4ab9168dec6cc1dbab19cad31bc887e
sha512: 1b5ab23c209f55132e58e01f5ee9dec8420221d39cb15cbf3f398e1a61d24d7f59df9d67913c6b7807685940f0719297636c69845b5cbd51782827fe0dfccadc
ssdeep: 24576:twWHhK2FjW8WVKMnrLzkh7RoIPLAW5oa7L4IJSJRuMkasL1XR:eWHhKejW8gK0r/kh7RoIcW5RNJHra+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1213533236FD422A9E5BF4131AF2BA3C0BE306AA5CC19FF95B88058784D78172555B373
sha3_384: e42de5ff613b06af1a061a43fa820deed8c743033c89487a2b2e721bdb8e6887c394b24b071cd95cdf5560b1d4a5af57
ep_bytes: 60be001046008dbe0000faff5783cdff
timestamp: 2016-12-01 14:43:17

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileVersion: 15.0.23.0
LegalCopyright: Copyright 2016 Avira Operations GmbH & Co. KG. All rights reserved.
OriginalFilename: MailGuard_POP3.exe
ProductName: Avira Swat Apl Rs
ProductVersion: 15.0.23.0
Translation: 0x0809 0x04b0

Generik.EMYTNQT also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ramy.4!c
DrWebTrojan.BtcMine.1084
MicroWorld-eScanAIT.Heur.Ramy.1.B285E6D2.Gen
ClamAVWin.Malware.Autoit-6992293-0
FireEyeAIT.Heur.Ramy.1.B285E6D2.Gen
CAT-QuickHealTrojan.Autcobit
ALYacAIT.Heur.Ramy.1.B285E6D2.Gen
Cylanceunsafe
SangforTrojan.Win32.Autcobit.V8xr
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutCobit.55cfc2e3
K7GWTrojan ( 700000111 )
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.EMYTNQT
APEXMalicious
CynetMalicious (score: 99)
BitDefenderAIT.Heur.Ramy.1.B285E6D2.Gen
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Autcobit.Ijgl
EmsisoftAIT.Heur.Ramy.1.B285E6D2.Gen (B)
F-SecureTrojan.TR/AutCobit.slaiz
VIPREAIT.Heur.Ramy.1.B285E6D2.Gen
TrendMicroTROJ_GEN.R002C0DGR23
McAfee-GW-EditionBehavesLike.Win32.DLSponsor.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataWin32.Trojan.PSE.CDL9ON
AviraTR/AutCobit.slaiz
Antiy-AVLHackTool/Win32.Agent
ArcabitAIT.Heur.Ramy.1.B285E6D2.Gen [many]
MicrosoftTrojan:Win32/AutCobit
GoogleDetected
AhnLab-V3Trojan/Win32.Nymeria.C2495045
McAfeeArtemis!E8AA1D90BC23
MAXmalware (ai score=86)
VBA32Trojan.Autoit.Wirus
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGR23
RisingTrojan.Generic@AI.95 (RDML:tJAwHU/ip967qOQYJpdMhA)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.215134811.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.EMYTNQT?

Generik.EMYTNQT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment