Malware

Generik.ERMDMMG removal guide

Malware Removal

The Generik.ERMDMMG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ERMDMMG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Generik.ERMDMMG?


File Info:

crc32: A48BFECD
md5: b26df404d14331f49a0e34a4b3f0d9e0
name: B26DF404D14331F49A0E34A4B3F0D9E0.mlw
sha1: 2febec99d00bcc598729a7ad52a1f774cf9a5459
sha256: a40a22599feed7a3641983c1ea0d3e44335f5890a389d0a31eff50cd98a2e0ce
sha512: 24628b3b23c36e2f32504edf1437ae6755d45f6724aaa2c90bd6b8eaa2988077e84d1a154777f723ca4b419f9b241c27fea6bd0c48c3c09cf0e136c7d36e89e0
ssdeep: 24576:HQ9NQ7MyiN0Z/wbEQig66Lh0XHdHltpKLGy+yUvxQPE325:muIXN09wdLoHdHldtDqE325
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Hewlett-Packard 2017
Assembly Version: 1.0.0.0
InternalName: ICOMServerEntry.exe
FileVersion: 1.0.0.0
CompanyName: Hewlett-Packard
LegalTrademarks:
Comments:
ProductName: mPortal
ProductVersion: 1.0.0.0
FileDescription: mPortal
OriginalFilename: ICOMServerEntry.exe

Generik.ERMDMMG also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/starter.ali1000139
CyrenW32/Trojan.SW.gen!Eldorado
SymantecScr.Malcode!gdn30
ESET-NOD32a variant of Generik.ERMDMMG
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.46189986
MicroWorld-eScanTrojan.GenericKD.46189986
Ad-AwareTrojan.GenericKD.46189986
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34684.6m0@a8nMMBd
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FireEyeTrojan.GenericKD.46189986
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_77%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/NanoBot.RKC!MTB
GDataMSIL.Trojan-Stealer.AgentTesla.FC6CSI
McAfeeRDN/Generic.rp
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_GEN.F0D1C00DR21
RisingMalware.Undefined!8.C (CLOUD)
IkarusWin32.Outbreak
FortinetPossibleThreat.PALLASNET.H
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.ERMDMMG?

Generik.ERMDMMG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment