Malware

Generik.GIPIBPZ (file analysis)

Malware Removal

The Generik.GIPIBPZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GIPIBPZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.GIPIBPZ?


File Info:

crc32: 0ADF392C
md5: b37a644b9e8d385df8b449bc1d34e6f2
name: winlog.exe
sha1: 06d1ad1cd885804691d141c07acf7a7b4f5fc36d
sha256: eac389ec08c1e73daba4f32467172d8fea59dbc935da8db60052493802810978
sha512: b85bbbabf9eaa4adb10ada0184e3ed4d9697a3d37a7ba2ef2622b0d6a602e2fc08ccd0e5e5c0a198f04cbc9529873f5004a6b6dd2ae3b79ebd8590646a14c300
ssdeep: 12288:MKN9o9h09kIkDW8TIhmXygDTjhRrhX+mAyG/B:Mi9o9JHtMAfT7FX+mABB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) 2007-2015 Unity Technologies
InternalName: Satisfied Stick
CompanyName: Unity Technologies
ProductName: Satisfied Stick
ProductVersion: 7.2.2.664
FileDescription: Plays Nces Closed
OriginalFilename: Satisfied Stick.exe
Translation: 0x0409 0x04b0

Generik.GIPIBPZ also known as:

MicroWorld-eScanGen:Variant.Razy.586070
FireEyeGeneric.mg.b37a644b9e8d385d
ALYacGen:Variant.Razy.586070
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Razy.586070
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.32515.FmKfa8QTAUni
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Generickdz-6907156-0
GDataGen:Variant.Razy.586070
KasperskyTrojan-Downloader.Win32.Deyma.ars
AegisLabTrojan.Multi.Generic.4!c
RisingStealer.Amadey!1.BC27 (CLASSIC)
Ad-AwareGen:Variant.Razy.586070
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Zlob.nelvv
Invinceaheuristic
Trapminesuspicious.low.ml.score
IkarusWin32.Outbreak
AviraTR/AD.Zlob.nelvv
Endgamemalicious (moderate confidence)
ArcabitTrojan.Razy.D8F156
ZoneAlarmTrojan-Downloader.Win32.Deyma.ars
MicrosoftTrojan:Win32/Tiggre!plock
McAfeeRDN/Generic.dx
MAXmalware (ai score=85)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Generik.GIPIBPZ
FortinetW32/PossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM11.1.7AEB.Malware.Gen

How to remove Generik.GIPIBPZ?

Generik.GIPIBPZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment