Malware

Generik.CXAFSBM removal tips

Malware Removal

The Generik.CXAFSBM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CXAFSBM virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to remove evidence of file being downloaded from the Internet
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rodasiter.duckdns.org

How to determine Generik.CXAFSBM?


File Info:

crc32: 32229CF4
md5: c3cef44271283e3927f9dc29476408f4
name: C3CEF44271283E3927F9DC29476408F4.mlw
sha1: 54f1b0c2ab05509de89e7d02d392a2b49de66c3b
sha256: 53299a3abf2f47ef272581bd972211a016d6693f124537d8253f0d5b7990d0cc
sha512: 23fd85da5fca300595de81c5d9f4c10138354c6c8dd6b0923b23918d3b5b8027fe006a10c993d31ec94cd7e08fb65bc6e4a7a50e47782beedba1b10f159a54d9
ssdeep: 12288:MAVp6I6A3js2aLnhH2FAutWZNS5JyFbgB1t6gMvlTpa6NYjHhtkakB1t6gMvlTp:MA4A3jvAuJJy41Ea1jBHe1Ea1jBHzu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: AtlSafeArray
FileVersion: 1.0.0.1
ProductName: AtlSafeArray Module
ProductVersion: 1.0.0.1
FileDescription: AtlSafeArray Module
OriginalFilename: AtlSafeArray.DLL
Translation: 0x0409 0x04b0

Generik.CXAFSBM also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.45217767
FireEyeGeneric.mg.c3cef44271283e39
McAfeeGenericRXAA-FA!C3CEF4427128
CylanceUnsafe
K7AntiVirusTrojan ( 005755ec1 )
BitDefenderTrojan.GenericKD.45217767
K7GWTrojan ( 005755ec1 )
CyrenW32/Trojan.VWAD-1921
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.AveMaria.gen
AlibabaTrojanSpy:Win32/AveMaria.bf1cf39d
ViRobotTrojan.Win32.Z.Wacatac.1780736
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareTrojan.GenericKD.45217767
EmsisoftTrojan.GenericKD.45217767 (B)
ComodoMalware@#ggj71vat02ey
F-SecureTrojan.TR/Spy.AveMaria.buhuc
DrWebTrojan.KillProc2.14935
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/Spy.AveMaria.buhuc
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA53
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Generic.D2B1F7E7
ZoneAlarmHEUR:Trojan-Spy.Win32.AveMaria.gen
GDataTrojan.GenericKD.45217767
CynetMalicious (score: 100)
ALYacTrojan.PSW.AveMaria
VBA32BScope.TrojanBanker.Emotet
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.CXAFSBM
TrendMicro-HouseCallTROJ_GEN.F0D1C00LS20
TencentWin32.Trojan-spy.Avemaria.Szbq
FortinetW32/Generik.CXAFSBM!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.39B3.Malware.Gen

How to remove Generik.CXAFSBM?

Generik.CXAFSBM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment