Malware

Generik.HJOIBTU malicious file

Malware Removal

The Generik.HJOIBTU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HJOIBTU virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.HJOIBTU?


File Info:

name: E0D46F36A32DF5F8927F.mlw
path: /opt/CAPEv2/storage/binaries/1412d7dacd4e4aa6ff81aede01d239701a40d5271bde1fb440b5d45d3208dcaf
crc32: 2A5657E8
md5: e0d46f36a32df5f8927f78d49d53a810
sha1: 1fa2bec6c7cb6c0aba90b05c06ccbf76f088ae14
sha256: 1412d7dacd4e4aa6ff81aede01d239701a40d5271bde1fb440b5d45d3208dcaf
sha512: 81e91c12b10d849edad9af80d1f6b5900a1f71df3042ede6bda30c723054554eb62ef6114384f4733cb1153378194f27ce6e8b5e96df6df95c775acdb39e17a9
ssdeep: 98304:ExESE/Fq7T3JHvVk6prdf0xC06fSCwsejIqV5jMNvCYRh:Fk7ty6pp0c06fSCY9VBECI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1063353F6DA81F6F0514CB2B52D275DD3BCBDA67B60810F43865E3B49B10826838E6E
sha3_384: 919cb5cb613b860a897fd953f9b4b17a7444ab07274edf5522f0662681d477e40df91e1cd0bce8f856edd4f849b0aace
ep_bytes: e88f28000050e8cb2901000000000090
timestamp: 2006-12-03 09:53:00

Version Info:

0: [No Data]

Generik.HJOIBTU also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanTrojan.GenericKD.63799730
FireEyeTrojan.GenericKD.63799730
CylanceUnsafe
SangforTrojan.Win32.Ekstak.Vi79
AlibabaTrojan:Win32/Ekstak.a8ef4e02
BitDefenderThetaGen:NN.ZedlaF.34796.em4aaSLi9xd
CyrenW32/Risk.DMLV-4181
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.HJOIBTU
TrendMicro-HouseCallTROJ_GEN.R002C0RKM22
ClamAVWin.Trojan.OnlineGames-1590
KasperskyTrojan.Win32.Ekstak.akjru
BitDefenderTrojan.GenericKD.63799730
NANO-AntivirusTrojan.Win32.Agent.deioen
CynetMalicious (score: 99)
AvastWin32:Malware-gen
RisingTrojan.Win32.Generic.1331083C (C64:YzY0OmvPQI4Iv5in)
Ad-AwareTrojan.GenericKD.63799730
SophosMal/Generic-L
ComodoMalware@#1uvdqq6bjih4o
DrWebTrojan.Siggen19.11090
TrendMicroTROJ_GEN.R002C0RKM22
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
EmsisoftTrojan.GenericKD.63799730 (B)
APEXMalicious
GDataWin32.Trojan.PSE.1M9I3UI
AviraTR/Ekstak.khohz
Antiy-AVLWorm/Win32.AutoRun
KingsoftWorm.Autorun.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!E0D46F36A32D
MAXmalware (ai score=81)
VBA32BScope.TrojanDropper.Convagent
MalwarebytesMalware.Heuristic.1003
TencentWin32.Trojan.Ekstak.Kjgl
YandexTrojan.GenAsa!i5W4JG7pFAk
FortinetW32/Malware_fam.NB
AVGWin32:Malware-gen

How to remove Generik.HJOIBTU?

Generik.HJOIBTU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment