Malware

What is “Generik.LHDYHSF”?

Malware Removal

The Generik.LHDYHSF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LHDYHSF virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Anomalous binary characteristics

How to determine Generik.LHDYHSF?


File Info:

crc32: 602F08E8
md5: e9d4ccf9ac74ab355ca35ccabcac6cb6
name: E9D4CCF9AC74AB355CA35CCABCAC6CB6.mlw
sha1: a3ac9abd04b64db6fa6bb7d232915bc5dd62e308
sha256: 473421b1492dc378367318dcd721a4085650014acb112f8141ca7711ae11cdfa
sha512: 6d6aec5ef41153d5ea25107041b832d7a723fc46fbdf7a3df074d5974407cde8a7b46cc78da0a314749ffc71b35001f062e78eeafba9864460b69940c586bda6
ssdeep: 24576:uBOVCV3FsrDo0sjrOq0FhmfIsM93uZ6f2xnkTSBhXmxY:uBOVC0HofHmFhiRM93dOOyP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2016 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.7.1.3901
CompanyName: Oleg N. Scherbakov
PrivateBuild: April 1, 2016
ProductName: 7-Zip SFX
ProductVersion: 1.7.1.3901
FileDescription: 7z Setup SFX (x86)
OriginalFilename: 7ZSfxMod_x86.exe
Translation: 0x0000 0x04b0

Generik.LHDYHSF also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.PWS.Siggen2.64116
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46012838
ZillyaTrojan.GenericKD.Win32.232347
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Stealer.92ae6740
K7GWTrojan ( 00579fbf1 )
K7AntiVirusTrojan ( 00579fbf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LHDYHSF
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Spy.Win32.Stealer.yea
BitDefenderTrojan.GenericKD.46012838
MicroWorld-eScanTrojan.GenericKD.46012838
Ad-AwareTrojan.GenericKD.46012838
SophosMal/Generic-S
ComodoMalware@#2bs78eov5dkk3
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.e9d4ccf9ac74ab35
EmsisoftTrojan.GenericKD.46012838 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Injuke.duj
WebrootW32.Trojan.Gen
AviraTR/Spy.Stealer.weuzv
KingsoftWin32.Troj.Stealer.y.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA47
ArcabitTrojan.Generic.D2BE19A6
AegisLabTrojan.Win32.Stealer.trMm
ZoneAlarmTrojan-Spy.Win32.Stealer.yea
GDataWin32.Trojan-Spy.CryptBot.BTVC4A
AhnLab-V3Trojan/Win32.Yakes.C1818906
McAfeeArtemis!E9D4CCF9AC74
MAXmalware (ai score=81)
VBA32BScope.Trojan.Agent
PandaTrj/CI.A
IkarusTrojan.SuspectCRC
FortinetW32/Generik.LHDYHSF!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Generic.HgIASSAA

How to remove Generik.LHDYHSF?

Generik.LHDYHSF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment