Malware

About “Generik.GBBRQVU” infection

Malware Removal

The Generik.GBBRQVU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GBBRQVU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

email.yg9.me
ip-api.com
iw.gamegame.info
ol.gamegame.info
redirector.gvt1.com

How to determine Generik.GBBRQVU?


File Info:

crc32: 294C3C82
md5: 26a2014da76c70d223a918888a444e42
name: 26A2014DA76C70D223A918888A444E42.mlw
sha1: c6aafb67d3aa0495fa32de8c3fe1fd256bfcb199
sha256: 22811245067eb0e6e0a6a0696a69a02679221e02e41193939699e6657be11f6c
sha512: eb52bf7acc36c5903da582f0836c2fec2acae5d6eb5996f6bdf2f7bc7b42ba019f41d2b8f6b7cbe6a02ed09dbca5b0c4d4d064f2646bc7eb6533f830ce43d363
ssdeep: 12288:Umn1vBXNJl0P3ZbcCAjqH0d5g+qUH6wyZQMvvdgMiCgT:n1vJNJla39cGH0dG7sOlQCgT
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Logitech, Inc. 2021
InternalName: Logitech G HUB
FileVersion: 2021.6.4851
CompanyName: Logitech, Inc.
ProductName: LGHUB Crashpad Handler
ProductVersion: 2021.6.4851
FileDescription: LGHUB Crashpad Handler
Translation: 0x0409 0x04e4

Generik.GBBRQVU also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject4.12781
ALYacTrojan.GenericKD.37122015
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.GBBRQVU
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Downloader.Win32.Zenlod.gen
BitDefenderTrojan.GenericKD.37122015
MicroWorld-eScanTrojan.GenericKD.37122015
Ad-AwareTrojan.GenericKD.37122015
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.26a2014da76c70d2
EmsisoftTrojan.GenericKD.37122015 (B)
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Script/Phonzy.B!ml
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKD.37122015
McAfeeArtemis!26A2014DA76C
MAXmalware (ai score=86)
PandaTrj/CI.A
IkarusTrojan.SuspectCRC
FortinetW32/PossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generik.GBBRQVU?

Generik.GBBRQVU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment