Malware

Should I remove “Generik.BKXJAHI”?

Malware Removal

The Generik.BKXJAHI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.BKXJAHI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Generik.BKXJAHI?


File Info:

crc32: B61DDB8B
md5: 9996e142124324bdd491f988e54145d6
name: txt.exe
sha1: ee492dc63af3aad852fe1f204c936c3a176d6ec4
sha256: 0e15755182ba43c7300ddca400f4029bd5b1d69201f2d393d5291c47643e8115
sha512: 5fcb2ce9abea8398b02cf3714c820c2dd0b6ab2747d70846fdf09e3f5ed0b062d31c2e889d1c649571a9037ad4ddb8368349691df2e5621975b9be05fab4b9ab
ssdeep: 49152:ETMCXpmTg5cyDXxe0Uepz3X18ZrO8ahRNdp2m14h09EzKvqZH3XGVHjepHtBRF5G:Gpmc5c6NUmznwa/8mSh09EYql2ZetTbk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: vvWMIEGzFPVYTlgIdACbna.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: vvWMIEGzFPVYTlgIdACbna.exe

Generik.BKXJAHI also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanTrojan.GenericKD.42831690
Qihoo-360Generic/HEUR/QVM19.1.C369.Malware.Gen
McAfeeArtemis!9996E1421243
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42831690
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroTROJ_GEN.R002C0WCB20
BitDefenderThetaGen:NN.ZexaF.34100.pF0@aCBTKhi
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42831690
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.fa4021b2
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.Z.Agent.3404375
RisingTrojan.Kryptik!1.C2F5 (CLOUD)
Ad-AwareTrojan.GenericKD.42831690
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Nymaim.wc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9996e142124324bd
EmsisoftTrojan.GenericKD.42831690 (B)
IkarusTrojan.Crypt
CyrenW32/Trojan.PZVM-8243
JiangminTrojan.Banker.ClipBanker.nd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Occamy
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28D8F4A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.AgentTesla.C4008301
Acronissuspicious
VBA32BScope.TrojanPSW.Agent
ALYacTrojan.GenericKD.42831690
MAXmalware (ai score=100)
PandaTrj/CI.A
ESET-NOD32a variant of Generik.BKXJAHI
TrendMicro-HouseCallTROJ_GEN.R002C0WCB20
TencentWin32.Trojan.Generic.Hvja
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_73%
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Cybereasonmalicious.63af3a
Paloaltogeneric.ml

How to remove Generik.BKXJAHI?

Generik.BKXJAHI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment