Malware

Generik.MHAAGRU malicious file

Malware Removal

The Generik.MHAAGRU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MHAAGRU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
kejittdgwbennils.su
yfcfqbalagqr.pl
qnlwouy.pw
hqptvpincsm.info
thvmqculkweq.su
lgvqqfdvqokvtv.su
mgwmrpmsgonexagu.ru

How to determine Generik.MHAAGRU?


File Info:

crc32: DD9A939C
md5: aaa5ff137c6b917e0afad70b1f2e7992
name: AAA5FF137C6B917E0AFAD70B1F2E7992.mlw
sha1: cca73af0c01a19e82b3a35dd919af1b45b27afc4
sha256: cc82715ce8be2e31cdd38159b4af9b494fa0701d6cc9ce4a75085e0ec828f552
sha512: 8329efa22c7244a208e7c52537be70fa1bfd8b2170564abaa54753a4762bd72e0eb2ed70635df307aa677b38f69923c8d0a3cd0514f3a4396561e0247ecd0270
ssdeep: 3072:pXMXiXMmxbiyWjzQ3j64V7GHD7mGfxkewYtadjvpXHh8uDzgZ9UYfGWB:pXMXxAbiNzM7GOG2FmS7dB8vnlP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

filedescription: Longlines
fileversion: 52.62.58.119
companyname: Reglues Superintendents
Translation: 0x0205 0x0586

Generik.MHAAGRU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
CAT-QuickHealRansom.Locky.D6
ALYacGen:Trojan.Heur2.RP.lu0@baK6@rfi
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.110157
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.37c6b9
BaiduWin32.Trojan.Kryptik.awy
CyrenW32/Locky.BD.gen!Eldorado
SymantecRansom.Locky!g13
ESET-NOD32a variant of Generik.MHAAGRU
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur2.RP.lu0@baK6@rfi
NANO-AntivirusTrojan.Win32.Ransom.evlocn
MicroWorld-eScanGen:Trojan.Heur2.RP.lu0@baK6@rfi
TencentWin32.Trojan.Ransom.Lpbh
Ad-AwareGen:Trojan.Heur2.RP.lu0@baK6@rfi
SophosML/PE-A + Mal/Ransom-EE
ComodoMalware@#1f80uuedsfpdx
BitDefenderThetaAI:Packer.5100209B20
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SMBOS2
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.aaa5ff137c6b917e
EmsisoftGen:Trojan.Heur2.RP.lu0@baK6@rfi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cryptor.qw
AviraHEUR/AGEN.1121498
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Locky
ArcabitTrojan.Heur2.RP.E5CC52
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Trojan.Heur2.RP.lu0@baK6@rfi
AhnLab-V3Trojan/Win32.RL_Autoit.R283737
Acronissuspicious
McAfeeRansomware-FRV!AAA5FF137C6B
MAXmalware (ai score=100)
MalwarebytesRansom.Locky.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPLOCKY.SMBOS2
RisingTrojan.Generic@ML.90 (RDML:MoVWQu/gSMwvQ0olJk6mRg)
YandexTrojan.Agent!/eyo9OtbAj4
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.FFBI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.MHAAGRU?

Generik.MHAAGRU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment