Malware

How to remove “Generik.HOXYFLR”?

Malware Removal

The Generik.HOXYFLR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HOXYFLR virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Generik.HOXYFLR?


File Info:

name: B88F06B660F19051980E.mlw
path: /opt/CAPEv2/storage/binaries/949e190299f3f1858fdad901410d610325680003a0402f0db39e8b48187f3ebf
crc32: 231D5EB2
md5: b88f06b660f19051980e23697882788f
sha1: c61f6e4a216d3bf9979ca34680e990ecbdaec860
sha256: 949e190299f3f1858fdad901410d610325680003a0402f0db39e8b48187f3ebf
sha512: c9ed259bce9020d48071ef5eb971f08db709404f068f2ac2d1396eb61fd86c6c4395fbbd3c17cb9dd353de713933d940f139a3f2a968ef5928ece77bcef18358
ssdeep: 98304:RbX3CtjyrdguKdonlmGjYoBtuivlbgLl1H7iza:xKjK2jKlmG5vuiZg51H7iza
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC060184A29384EEC1251C34FFF51733163DAFB92BD04AAA92A0F5EB55309BCF11D952
sha3_384: 285df8fdf94b51a23735f0d664a7e69f46e92cd733b6057634a8b0110f41d49b2c443fa559daf7ff0e0bcb761329daa8
ep_bytes: e884040000e988feffff3b0d68d64300
timestamp: 2020-06-25 10:38:24

Version Info:

0: [No Data]

Generik.HOXYFLR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Fsysna.4!c
MicroWorld-eScanGen:Variant.Ser.Ursu.22642
ClamAVWin.Malware.Bulz-9825042-0
FireEyeGeneric.mg.b88f06b660f19051
ALYacGen:Variant.Ser.Ursu.22642
Cylanceunsafe
SangforTrojan.Win32.Zenpack.ml
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Fsysna.891df4ea
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.HOXYFLR
ZonerProbably Heur.RARAutorun
APEXMalicious
AvastWin64:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Fsysna.htlk
BitDefenderGen:Variant.Ser.Ursu.22642
SophosMal/Generic-S
VIPREGen:Variant.Ser.Ursu.22642
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Ser.Ursu.22642 (B)
GDataGen:Variant.Ser.Ursu.22642
Antiy-AVLTrojan/Win64.Generic
ArcabitTrojan.Ser.Ursu.D5872
ZoneAlarmTrojan.Win32.Fsysna.htlk
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Gen.Reputation.C4301995
McAfeeArtemis!B88F06B660F1
MAXmalware (ai score=86)
VBA32BScope.Trojan.VBS.Agent
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
YandexTrojan.Fsysna!H4L4MbzM/k4
IkarusTrojan.Scar
MaxSecureTrojan.Malware.1728101.susgen
AVGWin64:MalwareX-gen [Trj]
Cybereasonmalicious.660f19
DeepInstinctMALICIOUS

How to remove Generik.HOXYFLR?

Generik.HOXYFLR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment