Malware

Generik.IPHPQGN removal guide

Malware Removal

The Generik.IPHPQGN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.IPHPQGN virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Connects to Tor Hidden Services through a Tor gateway
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
7tno4hib47vlep5o.tor2web.org
7tno4hib47vlep5o.tor2web.blutmagie.de
7tno4hib47vlep5o.tor2web.fi

How to determine Generik.IPHPQGN?


File Info:

crc32: 643284A3
md5: 081fd45ea4d05bb46ba24e7b27acae26
name: 081FD45EA4D05BB46BA24E7B27ACAE26.mlw
sha1: 9f6bffea71f9d1988f7db90ecc80ebbfbb190f93
sha256: e6f08632c5a2a18c33d23d42ada4597d60eca4bd40a676ecc6d0192a57345c0b
sha512: 699111ed604136db185bf01f4674d1c13a9cb7a16732ed3d1b17caf2ac2ad0f903075dc330e036e5bccd30bb6be3fca0f4f1548ad138903ed01e9c49932f78af
ssdeep: 24576:O+aCswXnlINrOsvwkOxIL9NKpdySsGEfVxbqSUZCld5j8cZPfz6R5vIrRHX1/HZ:8d9MV/h
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.IPHPQGN also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGeneric.mg.081fd45ea4d05bb4
McAfeeArtemis!081FD45EA4D0
VIPRETrojan.Win32.Generic!BT
SangforRansom.Win32.Bitman.adur
K7AntiVirusTrojan ( 005380781 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 005380781 )
BitDefenderThetaGen:NN.ZexaCO.34590.0nW@aCCPdsoi
SymantecTrojan Horse
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Bitman.adur
NANO-AntivirusTrojan.Win32.Bitman.fffcmt
RisingRansom.Tescrypt!8.3AF (CLOUD)
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Generic-S
ComodoMalware@#2w53fhi5mdmsy
F-SecureTrojan.TR/TeslaCrypt.tzrgz
McAfee-GW-EditionBehavesLike.Win32.Downloader.tm
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
IkarusTrojan-Ransom.TeslaCrypt
AviraTR/TeslaCrypt.tzrgz
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmTrojan-Ransom.Win32.Bitman.adur
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 85)
VBA32TrojanRansom.Bitman
ALYacGen:Heur.Ransom.REntS.Gen.1
MalwarebytesRansom.TeslaCrypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.IPHPQGN
TencentWin32.Trojan.Bitman.Dlf
FortinetW32/Generik.IPHPQGN!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ea4d05
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Bitman.HgIASOgA

How to remove Generik.IPHPQGN?

Generik.IPHPQGN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment