Malware

Generik.GANGEDM (file analysis)

Malware Removal

The Generik.GANGEDM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GANGEDM virus can do?

  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.GANGEDM?


File Info:

crc32: F716953C
md5: 27bea0a8734fff09dca23012988a7de3
name: 27BEA0A8734FFF09DCA23012988A7DE3.mlw
sha1: e4d227eee62a0f9d3b6cc84e95f1e5ac78e73575
sha256: 2e716b0cbe7ff80c296df141320e4470e170a9f93e81243e9d888bfcb27eec17
sha512: 809c85e27b56fcaf82566153cb282121791c0360fc38ef03fffaf418e3cf6275417c946490cfece43db18dfb5f8266d94559d8cb88d262e0593debb2545aae92
ssdeep: 24576:5tb20pkaCqT5TBWgNQ7auDNH8L16Cbgg0JisoocsWMfvu6A:KVg5tQ7auJI/f0JijsC5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2005-2014 copyright JWTS
ProductVersion: 7.70
FileVersion: 7.70.0.0
Comments: Alternative to Citrix
FileDescription: SetupProgram
Translation: 0x0809 0x04b0

Generik.GANGEDM also known as:

CylanceUnsafe
K7GWTrojan ( 00526faa1 )
K7AntiVirusTrojan ( 00526faa1 )
ESET-NOD32a variant of Generik.GANGEDM
APEXMalicious
AvastFileRepMetagen [Malware]
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Dwn.ewthso
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
WebrootTrojan.Dropper.Gen
eGambitUnsafe.AI_Score_69%
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!27BEA0A8734F
VBA32TrojanDropper.Agent
YandexTrojan.AvsArher.bTJisY
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.BJTFTR!tr
AVGFileRepMetagen [Malware]

How to remove Generik.GANGEDM?

Generik.GANGEDM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment