Malware

Generik.MGPOAUG removal guide

Malware Removal

The Generik.MGPOAUG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MGPOAUG virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mayserver-bamzy.ddns.net

How to determine Generik.MGPOAUG?


File Info:

crc32: DA5E91B0
md5: 3ba622df311df18ba36585a6e77ea4e4
name: ptr.exe
sha1: 507566c87db5834b0f7eed52db036a56f1c49607
sha256: f5fbae1207fc9f060fd6a8c4db58c89e1abe5e8283d24fe11c9e3cde38e83016
sha512: 82fe7cdbbd34ae766335dfa82d742ae0d251f7d8841df51e27bed02f5678c7b9d0da5f6a523ec76b29d3b4a0f2c74d38a71c5f504970aedfab560894badb685b
ssdeep: 49152:6l5HQiwBGfH1FjzFlL+v+9mb2JKsMXIrvJKtORizuQJIMQSTTE9z9IG:ytZN+J2JKatKtaQuQvE9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: xpsrchvw.exe
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: XPS Viewer
OriginalFilename: xpsrchvw.exe
Translation: 0x0409 0x04b0

Generik.MGPOAUG also known as:

MicroWorld-eScanTrojan.GenericKD.33920960
FireEyeGeneric.mg.3ba622df311df18b
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.33920960
APEXMalicious
GDataTrojan.GenericKD.33920960
KasperskyBackdoor.Win32.NetWiredRC.lag
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Backdoor.Netwiredrc.Lmuw
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
EmsisoftTrojan.GenericKD.33920960 (B)
IkarusBackdoor.Win32.NetWireRC
ArcabitTrojan.Generic.D20597C0
ZoneAlarmBackdoor.Win32.NetWiredRC.lag
MicrosoftPUA:Win32/Presenoker
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.33920960
PandaTrj/CI.A
ESET-NOD32a variant of Generik.MGPOAUG
SentinelOneDFI – Suspicious PE
FortinetW32/NetWiredRC.LAG!tr.bdr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.5d7

How to remove Generik.MGPOAUG?

Generik.MGPOAUG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment