Malware

Generik.NBHYPDN removal tips

Malware Removal

The Generik.NBHYPDN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NBHYPDN virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

email.yg9.me
ip-api.com
iw.gamegame.info
ol.gamegame.info

How to determine Generik.NBHYPDN?


File Info:

crc32: 4D27C120
md5: 643cf39469bca59a293b7d6837106f4c
name: 643CF39469BCA59A293B7D6837106F4C.mlw
sha1: fd1b4ec124c4086736a07a23cee27892ceb10d2f
sha256: 421b0a7152dfe73bcaae17fa1b6efa1ea2778f6428bb15938dcd4e3be5690c2d
sha512: 6954017662d2409c187a7647fa208778f69159a2866d0ba22b5d452aec85cb6410cc750af2bfaf62fcc8440b5f5b5e74a917cb7365bc9d15bed2e69a0d659f4f
ssdeep: 12288:Umn1vBX6Jl0P3ZbcCAjqH0d5CbUUH6wyZQMvvdgMiCPP:n1vJ6Jla39cGH0d04sOlQCPP
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Logitech, Inc. 2021
InternalName: Logitech G HUB
FileVersion: 2021.6.4851
CompanyName: Logitech, Inc.
ProductName: LGHUB Crashpad Handler
ProductVersion: 2021.6.4851
FileDescription: LGHUB Crashpad Handler
Translation: 0x0409 0x04e4

Generik.NBHYPDN also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject4.12817
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.37122019
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanDownloader:Win32/Zenlod.91fc13b7
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NBHYPDN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Downloader.Win32.Zenlod.gen
BitDefenderTrojan.GenericKD.37122019
MicroWorld-eScanTrojan.GenericKD.37122019
Ad-AwareTrojan.GenericKD.37122019
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.643cf39469bca59a
EmsisoftTrojan.GenericKD.37122019 (B)
AviraTR/AD.Inject.wzhrm
eGambitUnsafe.AI_Score_92%
MicrosoftProgram:Win32/Wacapew.C!ml
GDataTrojan.GenericKD.37122019
AhnLab-V3Trojan/Win.Generic.R426623
McAfeeArtemis!643CF39469BC
PandaTrj/CI.A
IkarusTrojan.SuspectCRC
FortinetW32/Zenlod.NBHYPDN!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.NBHYPDN?

Generik.NBHYPDN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment