Malware

Should I remove “Generik.ESLBGGF”?

Malware Removal

The Generik.ESLBGGF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ESLBGGF virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
r4—sn-4g5e6nl6.gvt1.com
update.googleapis.com
redirector.gvt1.com
r1—sn-4g5edns6.gvt1.com

How to determine Generik.ESLBGGF?


File Info:

crc32: 27413450
md5: ce16fc1030bb1ce9922ff4e477d18c4c
name: upload_file
sha1: b9b052caa49a2c350b4e205e1a1cd9617b7179a7
sha256: 8e2fbc4c964111b43a2cd9eb1684f8e308b50d7c95311eb90e5d033d6363d800
sha512: ad2f9873c1a7ca31821badd9e023a23befe030d67b4d93b315545eeeddb6c3325ccd8bb36a5f865a6f39e43040c3ebbeb923e8f0fc29f97d776d9db528ce5a36
ssdeep: 768:coohDQxp7i6BoxY6H6+7A2SISF17MfHvOX2O+WptaJwSGor:coEDm5iSoxY6H6YA2Sv17NUCOXr
type: ELF 32-bit MSB executable, SPARC version 1 (SYSV), statically linked, stripped

Version Info:

0: [No Data]

Generik.ESLBGGF also known as:

DrWebLinux.Mirai.632
MicroWorld-eScanTrojan.Linux.Mirai.1
FireEyeTrojan.Linux.Mirai.1
McAfeeLinux/Mirai.l
BitDefenderThetaGen:NN.Mirai.34152
CyrenE32/Trojan.HOJR-8
SymantecTrojan.Gen.NPE
ESET-NOD32a variant of Generik.ESLBGGF
TrendMicro-HouseCallPossible_MIRAI.SMLBO14
AvastELF:Mirai-NP [Trj]
GDataTrojan.Linux.Mirai.1
KasperskyHEUR:Backdoor.Linux.Mirai.b
BitDefenderTrojan.Linux.Mirai.1
RisingBackdoor.Mirai!8.E05B (TFE:14:xhnHbgTr7NF)
Ad-AwareTrojan.Linux.Mirai.1
ComodoMalware@#tcmos7lz71o8
F-SecureMalware.LINUX/Mirai.ymhkk
ZillyaTrojan.Mirai.Linux.67054
TrendMicroPossible_MIRAI.SMLBO14
SophosMal/Generic-S
JiangminBackdoor.Linux.fbla
AviraLINUX/Mirai.ymhkk
Antiy-AVLTrojan[Backdoor]/Linux.Mirai.b
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ZoneAlarmHEUR:Backdoor.Linux.Mirai.b
CynetMalicious (score: 85)
ALYacTrojan.Linux.Mirai.1
MAXmalware (ai score=87)
TencentBackdoor.Linux.Mirai.waz
IkarusTrojan.Linux.Gafgyt
FortinetELF/Mirai.AEO!tr
AVGELF:Mirai-NP [Trj]
Qihoo-360Linux/Backdoor.6f4

How to remove Generik.ESLBGGF?

Generik.ESLBGGF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment