Malware

Generik.MORYKQV (file analysis)

Malware Removal

The Generik.MORYKQV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MORYKQV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com

How to determine Generik.MORYKQV?


File Info:

crc32: 4C8A2F27
md5: bf7a60f7db50489178123026d401f46d
name: invoice pdf.exe
sha1: 7e7679aac6e0e1403acacf90851e7e718efd847c
sha256: 38bbbf99f082ac15bf1bc1ec96f8df0d955bb7b0b7b64887ef8d9bbb036093f6
sha512: b0daf593b7d5c915ff4ca2d411ed7179d9e26f31cbb6b35b347b7a8c52bd8d3ac1942d9262d6e063b6a87bdac6f45f11b35a6074dc7bb850b2277b646967ff13
ssdeep: 12288:Pfh/ASNlXKlSw9JAaTopBTiswtztK4FNj8sb7pnV/Yr6km2NFrcv76ngKdHFJKM:nBRjXKTJtTopBm9j8cFnRMg1q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016 - 2020
Assembly Version: 7.1.5.0
InternalName: x686v.exe
FileVersion: 7.1.5.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Jumping Square
ProductVersion: 7.1.5.0
FileDescription: Jumping Square
OriginalFilename: x686v.exe

Generik.MORYKQV also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.435286
FireEyeGeneric.mg.bf7a60f7db504891
McAfeeArtemis!BF7A60F7DB50
CylanceUnsafe
AegisLabTrojan.MSIL.Taskun.4!c
SangforMalware
BitDefenderGen:Variant.Ursu.435286
Cybereasonmalicious.7db504
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Taskun.gen
Ad-AwareGen:Variant.Ursu.435286
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Ursu.435286 (B)
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.D3!ml
ArcabitTrojan.Ursu.D6A456
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataGen:Variant.Ursu.435286
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Infostealer.C4088627
BitDefenderThetaGen:NN.ZemsilF.34570.Xu0@aOp8srk
ALYacGen:Variant.Ursu.435286
VBA32CIL.HeapOverride.Heur
MalwarebytesBackdoor.Agent.PDL
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.MORYKQV
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.ESJW!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.MORYKQV?

Generik.MORYKQV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment