Malware

Generik.MHYAHOM removal tips

Malware Removal

The Generik.MHYAHOM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MHYAHOM virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.MHYAHOM?


File Info:

crc32: B22D1BF9
md5: 168953ad9555dfbf0b4d1ac85acf8409
name: vbc.exe
sha1: 0d81d4d802c66b81bf076936e37a19da158317f4
sha256: c952026fa7a76126cb614df1222b44de65c9ce0367da0dcb0799781ed99031f3
sha512: 21877e1e0581667d8c076ac6462c591dbee648722466af45021ffb5e0a93bbbcf09639270f24627f7c8e1af63d412644ededda8595095659b33a8c6b58605a10
ssdeep: 24576:Tu6Jx3O0c+JY5UZ+XC0kGso/WaoktbrBJm05Y3g8wvAn1jGtwCHCRgitWY:9I0c++OCvkGsUWalY1jAwcLY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: prproc
CompanyName: Microsoft.Uev.CscUnpinTool
ProductName: PnPUnattend
ProductVersion: 316, 354, 951, 677
FileDescription: secinit
OriginalFilename: WSReset.exe
Translation: 0x0000 0x04b0

Generik.MHYAHOM also known as:

MicroWorld-eScanGen:Trojan.Heur.AutoIT.2
McAfeeArtemis!168953AD9555
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.AutoIT.4!c
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.2
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
F-ProtW32/AutoIt.IJ.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
GDataGen:Trojan.Heur.AutoIT.2
KasperskyTrojan-PSW.MSIL.Agensla.gxe
AlibabaTrojan:Win32/Predator.a17cdc73
RisingTrojan.Obfus/Autoit!1.BD7E (CLASSIC)
Ad-AwareGen:Trojan.Heur.AutoIT.2
F-SecureTrojan.TR/Predator.hmjvh
DrWebTrojan.PWS.Siggen2.39371
McAfee-GW-EditionBehavesLike.Win32.Downloader.th
FireEyeGeneric.mg.168953ad9555dfbf
EmsisoftGen:Trojan.Heur.AutoIT.2 (B)
CyrenW32/AutoIt.IJ.gen!Eldorado
AviraTR/Predator.hmjvh
MAXmalware (ai score=82)
Endgamemalicious (high confidence)
ArcabitTrojan.Heur.AutoIT.2
ZoneAlarmTrojan-PSW.MSIL.Agensla.gxe
MicrosoftTrojan:Win32/Predator.BC!MTB
AhnLab-V3Win-Trojan/Autoinj05.Exp
Acronissuspicious
ALYacSpyware.AgentTesla
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Generik.MHYAHOM
TrendMicro-HouseCallTROJ_GEN.R002C0DKS19
IkarusTrojan.Win32.Predator
FortinetAutoIt/Injector.ECS!tr
BitDefenderThetaAI:Packer.44866B6B18
AVGFileRepMalware
Cybereasonmalicious.d9555d
Qihoo-360Win32/Trojan.PSW.672

How to remove Generik.MHYAHOM?

Generik.MHYAHOM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment