Malware

Should I remove “Generik.HJCSDY”?

Malware Removal

The Generik.HJCSDY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HJCSDY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the Snake malware family

How to determine Generik.HJCSDY?


File Info:

name: 7091684F6D958D8BBB0A.mlw
path: /opt/CAPEv2/storage/binaries/7bbfbb37c39b9f86adc6fda345c835cb256948cdc886b273c3215e4ccbbd877a
crc32: DAB1569F
md5: 7091684f6d958d8bbb0ae72d30ef3f93
sha1: 946ab60d8020ed0209f2fc5237020ed74e2bf2f8
sha256: 7bbfbb37c39b9f86adc6fda345c835cb256948cdc886b273c3215e4ccbbd877a
sha512: d9374aff01b656fd92c6e44e095ed958be11c07b84a2d65f569ee278960571ac2ab3f1f7960113b8438b69945274e1e6d888a07646d528136102b6aad8979ae8
ssdeep: 6144:yGi8XioJX4D0f2O7lKr+kl1hwAgIqzljVlFUvD0YtVVCbGEUvvCTGgXEFtAsl/uP:ioISjXqvD0nbG7UjUF/tuSlJBM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A84124BFED529EEDC12C7B8283FC96AF772AF9E5161196302D17A320CD2903443875A
sha3_384: 9fc3d6965cbd23ae526ab9d5044f3a496ea063bb35c9c646e0e2edfecdd0e76ed5d01cc45dffedec0a2e7364c4b0f978
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Generik.HJCSDY also known as:

LionicTrojan.Win32.Stealer.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38175098
FireEyeTrojan.GenericKD.38175098
ALYacTrojan.GenericKD.38175098
MalwarebytesTrojan.Injector
ZillyaTrojan.Stealer.Win32.20388
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b52a1 )
AlibabaTrojanPSW:Win32/Stealer.2046edd8
K7GWTrojan ( 0058b52a1 )
Cybereasonmalicious.f6d958
CyrenW32/Injector.ARF.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Generik.HJCSDY
TrendMicro-HouseCallTROJ_FRS.0NA103L621
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.anzdj
BitDefenderTrojan.GenericKD.38175098
NANO-AntivirusTrojan.Win32.Stealer.jiwdxo
ViRobotTrojan.Win32.Z.Snakekeylogger.406133
AvastWin32:Trojan-gen
TencentWin32.Trojan-qqpass.Qqrob.Agaz
Ad-AwareTrojan.GenericKD.38175098
EmsisoftTrojan.GenericKD.38175098 (B)
ComodoMalware@#3u15j0trk61m9
F-SecureHeuristic.HEUR/AGEN.1219108
DrWebTrojan.DownLoader44.9840
TrendMicroTROJ_FRS.0NA103L621
McAfee-GW-EditionRDN/Snakekeylogger
SophosMal/Generic-S
APEXMalicious
GDataMSIL.Trojan-Spy.SnakeKeylogger.ETKQJD
AviraHEUR/AGEN.1233594
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
SUPERAntiSpywareTrojan.Agent/Gen-Siggen
ZoneAlarmTrojan.Win32.Inject.anzdj
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Frs.R457217
McAfeeRDN/Snakekeylogger
VBA32TrojanPSW.Stealer
IkarusTrojan.NSIS.Agent
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.EQRK!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.HJCSDY?

Generik.HJCSDY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment