Malware

How to remove “Generik.EMZHTQZ”?

Malware Removal

The Generik.EMZHTQZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EMZHTQZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the PyInstaller malware family

How to determine Generik.EMZHTQZ?


File Info:

name: EC2105CD4CBFAD91282D.mlw
path: /opt/CAPEv2/storage/binaries/f06a07ffdc941cf7c310ca189b164d7b0a5110beb634aae30b69e36f1bb08b68
crc32: 93D78704
md5: ec2105cd4cbfad91282daba032d077ee
sha1: 3a40c17cbac58ed83560ada475e371f7cc8b18ba
sha256: f06a07ffdc941cf7c310ca189b164d7b0a5110beb634aae30b69e36f1bb08b68
sha512: 5c51db1a0b4320cbbdf4c27464b82c67f9bb242da381ed0692775d43613861c0217d957f735cb296f3eab7037687d8f92c4b5f54d94f770823dc1e02eeaca4b4
ssdeep: 393216:9zCFNeXKyCdhcIOelXgpK92lHYQfY79VKQoS:9zCm6XLwpi26Q49VT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185D6332BED5000A3C5B169FA4EE9D373B56C59A25B7C96AB03FC13930B653D02B3660D
sha3_384: 022e285e896ee54723ebd9973352569f52ca6564912248bbbd4dea76b0a7c225d7a6e04579b4061f5abe076a77ef1dd5
ep_bytes: e836050000e98efeffffcccccc575653
timestamp: 2017-12-11 15:10:30

Version Info:

0: [No Data]

Generik.EMZHTQZ also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.HiddenInstall.2!c
CAT-QuickHealTrojan.Riskware
SangforAdware.Win32.HiddenInstall.si
K7AntiVirusRiskware ( 00584baa1 )
AlibabaAdWare:Win32/HiddenInstall.dfe17605
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.cbac58
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.EMZHTQZ
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.HiddenInstall.si
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Generik.Akon
SophosGeneric PUA DK (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
ZoneAlarmnot-a-virus:AdWare.Win32.HiddenInstall.si
GDataWin32.Trojan.BSE.15DLKXI
AhnLab-V3Trojan/Win32.RL_Wacatac.R360434
McAfeeArtemis!EC2105CD4CBF
TrendMicro-HouseCallTROJ_GEN.R002H0DEA22
FortinetMalicious_Behavior.SB
AVGFileRepMalware [Misc]

How to remove Generik.EMZHTQZ?

Generik.EMZHTQZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment