Malware

Generik.ICVIUBA (file analysis)

Malware Removal

The Generik.ICVIUBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ICVIUBA virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Generik.ICVIUBA?


File Info:

crc32: 9A234B99
md5: 4157fe3c73c7aa5edb271ba4599f35ff
name: upload_file
sha1: 52ea5cb0a00b173c2b2c5e73277d64cd683034ca
sha256: af9048b2200480b1360dd874baa4f9d355b7aa3aa20510fd665173d25953455b
sha512: 4be9214c9a2b54be6b4fca08bb5564d3a94d01bcddf08fb224f4c9214b21111bc00c0ad02933144680cc092265f8f138f128e81072e0265d727d0640132af141
ssdeep: 3072:wBeY5kb0TUNAuBqVPlB11nBE7pFgTtXgFRh9X:wEYOb0TUquBqt7nB8pFUuFRh9X
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Quo., Author: Alicia Joly, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Oct 14 08:01:00 2020, Last Saved Time/Date: Wed Oct 14 08:01:00 2020, Number of Pages: 1, Number of Words: 2014, Number of Characters: 11481, Security: 8

Version Info:

0: [No Data]

Generik.ICVIUBA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanW97m.Downloader.IYY
FireEyeW97m.Downloader.IYY
McAfeeRDN/Generic.rp
VIPRETrojan-Downloader.W97M.Agent.jc (v)
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 005703b31 )
K7GWTrojan ( 005703b31 )
TrendMicroTrojan.W97M.EMOTET.SMBA
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTrojan.W97M.EMOTET.SMBA
AvastVBS:Malware-gen
ClamAVDoc.Malware.Emotet-9777972-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderW97m.Downloader.IYY
ViRobotDOC.Z.Agent.137301
RisingMalware.ObfusVBA@ML.94 (VBA)
Ad-AwareW97m.Downloader.IYY
EmsisoftTrojan-Downloader.Macro.Generic.BW (A)
ComodoMalware@#308tb4ce0sqau
F-SecureMalware.W97M/Emotet.XP
DrWebExploit.Siggen2.48635
InvinceaMal/DocDl-K
McAfee-GW-EditionRDN/Generic.rp
SophosMal/DocDl-K
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Emotet.XP
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitW97m.Downloader.IYY
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AVL
CynetMalicious (score: 85)
AhnLab-V3Downloader/MSOffice.Generic
ALYacTrojan.Downloader.DOC.Gen
ESET-NOD32a variant of Generik.ICVIUBA
TencentHeur.Macro.Generic.f.83f88e56
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.AVL!tr
AVGVBS:Malware-gen
Qihoo-360virus.office.qexvmc.1080

How to remove Generik.ICVIUBA?

Generik.ICVIUBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment