Malware

Generik.DHTRFCN malicious file

Malware Removal

The Generik.DHTRFCN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DHTRFCN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

api2.qt6.com

How to determine Generik.DHTRFCN?


File Info:

crc32: 4C23E102
md5: cba422c29e749f48d9c386bb0f98d9e2
name: zhangyueireader.exe
sha1: 43f355355a9f0fccd01a7bd9e6797ab781bc5934
sha256: f57a6ac464e2f2b244b26b4ac741e62dfce95a85507aa4617c19473953b53c90
sha512: 6cce2174c809384500251d7c3e5a56eece6a310c50a8d5ee8a1c58905c3b0dcf0258355650f45e34ec5af3c18ceb4e0f60f5bee22a49bf582c748512ca59fc6e
ssdeep: 98304:ibCM0rTucFC0va56PQJqoMb94i9ceIyD8tx5PpHz3B46TLxs5rW0LNP7+RWf1fj:iaTx6vqoM59cPxhHz3B46Zs5rb6Lo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 1.0.3.77
ProductVersion: 1.0.3.0
Translation: 0x0804 0x03a8

Generik.DHTRFCN also known as:

MicroWorld-eScanTrojan.GenericKD.30997386
FireEyeGeneric.mg.cba422c29e749f48
ALYacTrojan.GenericKD.30997386
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.30997386
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.29e749
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34084.@30@aGSnljci
F-ProtW32/Injector.NJ.gen!Eldorado
SymantecPUA.Gen.2
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.30997386
Kasperskynot-a-virus:AdWare.Win32.Adload.adfrf
AlibabaAdWare:Win32/Adload.4738df99
AegisLabAdware.Win32.Adload.2!c
AvastWin32:Malware-gen
TencentWin32.Adware.Adload.Tbii
Ad-AwareTrojan.GenericKD.30997386
SophosMal/Generic-S
ComodoMalware@#2nwqlhxsd589f
F-SecureDropper.DR/Delphi.Gen
ZillyaTrojan.GenericKD.Win32.156180
TrendMicroTROJ_INJECT.THFACAK
McAfee-GW-EditionBehavesLike.Win32.Pate.wc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.30997386 (B)
IkarusTrojan.Agent
CyrenW32/Injector.NJ.gen!Eldorado
JiangminAdWare.AdInst.a
MaxSecureTrojan.Malware.73519123.susgen
AviraDR/Delphi.Gen
MAXmalware (ai score=94)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1D8FB8A
ZoneAlarmnot-a-virus:AdWare.Win32.Adload.adfrf
Acronissuspicious
McAfeeArtemis!CBA422C29E74
VBA32TScope.Trojan.Delf
ESET-NOD32a variant of Generik.DHTRFCN
TrendMicro-HouseCallTROJ_INJECT.THFACAK
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generik.DHTRFCN!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.DHTRFCN?

Generik.DHTRFCN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment