Malware

About “Generik.GCDCLOH” infection

Malware Removal

The Generik.GCDCLOH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GCDCLOH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Generik.GCDCLOH?


File Info:

crc32: 5AE2A9C8
md5: 178b02a6e531bda0b68d1021098e230d
name: 178B02A6E531BDA0B68D1021098E230D.mlw
sha1: fd092ffeb58933f2ad5a1ddbe0b5c4275ebeccc8
sha256: b0ebbc1f2d3f36c587831ad72ef92f5b9783efb6a8729c3e194a4e97d569132c
sha512: 8efbe2b17aec4baebd59ae32eeef9cf15b063643b1e96be31bb000d0ee4e3130c2d1dcf3b59b476aad12ed1275cbb56a9c663cc26e7f474ec7db5a96e3456cd9
ssdeep: 3072:iT8Jbmhs6qLOUhFcsRg4PKhEj+15YSXWmbNMeySsqCuJ7j3iBteZCmcd7:b0hdqasGR4PKt1W87ySsqJj3cw4my
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.GCDCLOH also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45134328
FireEyeGeneric.mg.178b02a6e531bda0
CAT-QuickHealBackdoor.Emotet
McAfeeRDN/Emotet
MalwarebytesSpyware.RaccoonStealer
BitDefenderTrojan.GenericKD.45134328
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Emotet.AZE.gen!Eldorado
SymantecTrojan.Sakurel
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Emotet.gen
AlibabaTrojan:Win32/EmotetCrypt.c66b6cc9
ViRobotTrojan.Win32.Emotet.224768
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Backdoor.Emotet.Dyqt
Ad-AwareTrojan.GenericKD.45134328
SophosMal/Generic-S + Troj/Emotet-CUJ
F-SecureTrojan.TR/AD.Emotet.gdb
DrWebTrojan.Emotet.1056
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
EmsisoftTrojan.GenericKD.45134328 (B)
IkarusTrojan.SuspectCRC
JiangminBackdoor.Emotet.vb
AviraTR/AD.Emotet.gdb
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
GridinsoftSpy.Win32.Keylogger.oa!s1
ArcabitTrojan.Generic.D2B0B1F8
ZoneAlarmHEUR:Backdoor.Win32.Emotet.gen
GDataTrojan.GenericKD.45134328
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.C4276117
MAXmalware (ai score=85)
ESET-NOD32a variant of Generik.GCDCLOH
RisingTrojan.Kryptik!1.D06D (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Emotet.AZE!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
Qihoo-360Generic/Trojan.b39

How to remove Generik.GCDCLOH?

Generik.GCDCLOH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment