Malware

Generik.HHLPVXY information

Malware Removal

The Generik.HHLPVXY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HHLPVXY virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generik.HHLPVXY?


File Info:

crc32: E8C92043
md5: 4e31e8563b18cc75d7f31408434d7698
name: 7z1902-x64.exe
sha1: 7d96d269bf92875d3b719c3408301eb7791ccf28
sha256: 497a79027e21f47a322f8b9551c9a381f4b58c61f5cf89b05d766690f370ee98
sha512: 1111f71bdb8138904541948b99a97095ed89287e0b366b1726733ab38e92eeb366a4f9ae1695b36f64c564cc991710de3531e241a212ec2c6a83aa2b74968479
ssdeep: 24576:XQeCMHtBf6j+m5Gm+wQ+MaJcpH5CGdzJPi3eVSeXVI9VZ8IFC/:XQeDNBfC5dJcpH5VdzJPiuLl+bM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: frights reserved.
InternalName: Wast
FileVersion: 11.
CompanyName: MFeraoration
ProductName: IEraplorer
ProductVersion: 11.00.9600.16428
FileDescription: WiAextractor
OriginalFilename: I
Translation: 0x0409 0x04b0

Generik.HHLPVXY also known as:

MicroWorld-eScanTrojan.GenericKD.42319918
FireEyeTrojan.GenericKD.42319918
CAT-QuickHealTrojan.Alien
Qihoo-360Win32/Trojan.8f4
ALYacTrojan.GenericKD.42319918
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42319918
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HHLPVXY
TrendMicro-HouseCallTROJ_GEN.R011H0DB220
GDataTrojan.GenericKD.42319918
KasperskyTrojan.Win32.Alien.gxr
AlibabaTrojan:Win32/Alien.c656f24d
AegisLabTrojan.Win32.Alien.4!c
Ad-AwareTrojan.GenericKD.42319918
SophosMal/Generic-S
F-SecureTrojan.TR/Barys.kcihk
McAfee-GW-EditionArtemis!Trojan
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42319918 (B)
CyrenW32/Trojan.WFFZ-3875
WebrootW32.Malware.gen
AviraTR/Barys.kcihk
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D285C02E
ZoneAlarmTrojan.Win32.Alien.gxr
MicrosoftTrojan:Win32/Wacatac.C!ml
McAfeeArtemis!4E31E8563B18
MAXmalware (ai score=84)
PandaTrj/CI.A
IkarusTrojan.SuspectCRC
eGambitPE.Heur.InvalidSig
FortinetPossibleThreat.MU
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.HHLPVXY?

Generik.HHLPVXY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment