Malware

Generik.HAOJUZO (file analysis)

Malware Removal

The Generik.HAOJUZO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HAOJUZO virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generik.HAOJUZO?


File Info:

crc32: 79A67A56
md5: 54ec1837af4b47f9ad72d6544929d77b
name: mailer.exe
sha1: ed669c29000999f1910c2ab123bea8f21c711af3
sha256: e74d3dc9223a90187d6656ebe296647b83006b329950680d3ecd690f08525cc1
sha512: cb805815ef474729fe556bf095dbad1bdcdc1c9dfc738fb55594217c6e844c614ec74b0c3485a3b2716ada075c6940825a5d810e1f2845b6d2a441b805ee7b89
ssdeep: 768:HVv7JZthtNtNtNJlvmIAOtrv7uWVov4llccjKC:HVv7JZthtNtNtNJlvmIDtrv7fVovelVL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9Microsoft Corporation. All rights reserved
Assembly Version: 1.0.0.0
InternalName: ntoskrnl.exe
FileVersion: 1.0.0.0
Comments: NT Kernel & System
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 1.0.0.0
FileDescription: Registry
OriginalFilename: ntoskrnl.exe

Generik.HAOJUZO also known as:

MicroWorld-eScanGen:Variant.MSILPerseus.189251
FireEyeGeneric.mg.54ec1837af4b47f9
ALYacGen:Variant.MSILPerseus.189251
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.MSILPerseus.189251
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R011C0DCF20
BitDefenderThetaGen:NN.ZemsilF.34100.cm0@aW397fn
APEXMalicious
AvastWin32:Malware-gen
GDataMSIL.Trojan.Kryptik.OY
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
AlibabaVirTool:MSIL/Perseus.9278cf16
AegisLabTrojan.Win32.Perseus.4!c
TencentMsil.Trojan-banker.Clipbanker.Sxou
SophosMal/Generic-S
F-SecureTrojan.TR/ATRAPS.Gen
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.grp
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.MSILPerseus.189251 (B)
IkarusTrojan.Agent
CyrenW32/Trojan.ZINY-0677
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Banker]/MSIL.ClipBanker
MicrosoftVirTool:MSIL/Perseus.AB!MTB
ArcabitTrojan.MSILPerseus.D2E343
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
McAfeeArtemis!54EC1837AF4B
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.HAOJUZO
TrendMicro-HouseCallTROJ_GEN.R011C0DCF20
RisingMalware.Undefined!8.C (CLOUD)
YandexTrojan.Agent!GWuDU+nBAHU
SentinelOneDFI – Malicious PE
FortinetPossibleThreat
Ad-AwareGen:Variant.MSILPerseus.189251
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.f6f

How to remove Generik.HAOJUZO?

Generik.HAOJUZO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment