Malware

Generik.GHTJASD removal

Malware Removal

The Generik.GHTJASD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GHTJASD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Appends a known Sage ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

mbfce24rgn65bx3g.2kzm0f.com
mbfce24rgn65bx3g.l3nq0.net

How to determine Generik.GHTJASD?


File Info:

crc32: 3795395A
md5: f9caa3f707b521e54a11e582183a9238
name: F9CAA3F707B521E54A11E582183A9238.mlw
sha1: b9cd1a75495574b78cf0631d82bbd9bdbba91572
sha256: a41d766ecb83d616fdf8031f8c8c0e28f7b840e1a796b4badd06aec51c9f0e7e
sha512: 1cb12c14e2567781254a3c919a81d2549876d1cd8ce2b34168e254fba0102a2ced3b897117e65fc76c4d52b92182c5ebd4f1390ddd14f5908a5b92475bfb8626
ssdeep: 6144:ULqoLglZvNXte/iooSGrRg7CBEFkjB5/Yeuw+moByOi71p:U1sZ1X8/iooSGy7Uuylmwf5Oap
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generik.GHTJASD also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051d45f1 )
LionicTrojan.Win32.SageCrypt.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!F9CAA3F707B5
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/SageCrypt.e4d7fa8a
K7GWTrojan ( 0051d45f1 )
Cybereasonmalicious.707b52
SymantecTrojan Horse
ESET-NOD32a variant of Generik.GHTJASD
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.SageCrypt.czf
BitDefenderGen:Variant.Brresmon.196
NANO-AntivirusTrojan.Win32.SageCrypt.farekd
MicroWorld-eScanGen:Variant.Brresmon.196
TencentWin32.Trojan.Sagecrypt.Egek
Ad-AwareGen:Variant.Brresmon.196
SophosML/PE-A
ComodoMalware@#235eknnwh7orw
BitDefenderThetaGen:NN.ZexaF.34170.omHfaanBTnfi
TrendMicroMal_Cerber-23
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.f9caa3f707b521e5
EmsisoftGen:Variant.Brresmon.196 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.SageCrypt.os
AviraHEUR/AGEN.1124685
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.1ED56FF
MicrosoftRansom:Win32/Milicry.A
ArcabitTrojan.Brresmon.196
GDataGen:Variant.Brresmon.196
VBA32BScope.Trojan.Yakes
MAXmalware (ai score=88)
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Cerber-23
YandexTrojan.SageCrypt!PnHFIG4V0Zk
IkarusTrojan-Spy.Win32.PSWSteal
FortinetW32/SageCrypt.CZF!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Generik.GHTJASD?

Generik.GHTJASD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment