Malware

Generik.HYEITBG removal

Malware Removal

The Generik.HYEITBG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HYEITBG virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

volamnoibo.com
volam2.club
edgedl.me.gvt1.com

How to determine Generik.HYEITBG?


File Info:

crc32: FFE8E964
md5: 1d46827289d9ae8b53f8f7ae54f89000
name: 1D46827289D9AE8B53F8F7AE54F89000.mlw
sha1: aa74cc4eeff058a72551f2ed66a4313306bd4239
sha256: 67d57c4bb2d2048a9e3e41dae08b403d5b046fe85dc24a73fafde4d28ed38600
sha512: cf0dcef9d4145b81446d0a7ef62da0ffa6b5eb72ef8a994bbfad7ea44e3750f584b425bf080d1843aee3770a3cb02e2c9fceb2c8fe32f9703234b17bdd1f70df
ssdeep: 49152:c4nY0Be3tvk3BbDbjbZfVHbxaa2QUJ4KjLSBWk9qy5DQyTq:cWe3tm5bjBhVaa25lGNoyxQyT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Generik.HYEITBG also known as:

ALYacTrojan.GenericKD.46675699
CylanceUnsafe
SangforBackdoor.MSIL.Crysan.gen
AlibabaBackdoor:Win32/Crysan.b7b1a9bc
Cybereasonmalicious.289d9a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HYEITBG
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderTrojan.GenericKD.46675699
ViRobotTrojan.Win32.Z.Bulz.2734080
MicroWorld-eScanTrojan.GenericKD.46675699
Ad-AwareTrojan.GenericKD.46675699
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.Mo0@aSoAJzc
TrendMicroTROJ_GEN.R01FC0WGQ21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.1d46827289d9ae8b
EmsisoftTrojan.GenericKD.46675699 (B)
AviraBDS/Redcap.gwmmy
eGambitUnsafe.AI_Score_64%
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.46675699
McAfeeArtemis!1D46827289D9
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.AsyncRAT
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R01FC0WGQ21
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASZAA

How to remove Generik.HYEITBG?

Generik.HYEITBG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment