Malware

Generik.DOFLZKJ removal guide

Malware Removal

The Generik.DOFLZKJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DOFLZKJ virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Generik.DOFLZKJ?


File Info:

name: 9A918F9A6916C8F6D0F7.mlw
path: /opt/CAPEv2/storage/binaries/56f3b02f5ffb97bd37c897aa416439d4378b5c603d831ff0b66577b984b00302
crc32: 407D0164
md5: 9a918f9a6916c8f6d0f7374d78a3130d
sha1: cdbee61fda1c6982a3c63fe80744dc6ee111dae0
sha256: 56f3b02f5ffb97bd37c897aa416439d4378b5c603d831ff0b66577b984b00302
sha512: 80eaf1e39efc6f26aa0d75b748fba24eff78e1da89c09735f64e75b8aac6b9dceb7b0ede7e9d54fb6885e47f2c91a46d1637c6429880c5af4b1b991a029d2480
ssdeep: 6144:8Zyv1gfPS0vJZwXKfjTLSH63808ERF1CoK32nB/Ha+U:dWrU63d8EjgoK3iBS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7441242B9EA6823F4776BB166D752ECC6F6B4B425104B22BCA0084F3F22DA46753735
sha3_384: 6abe0d8927776e1a92f53d71999d49551cf53e9ed7a063738f5e5eaf5c8754a0b7c8ab91f8f2255bd2673f644cd0de9f
ep_bytes: 60be00e046008dbe0030f9ffc7879c10
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: C2H5OH
FileDescription:
FileVersion: 2.0.0.0
InternalName:
LegalCopyright: MaTyS
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 2.0.0.0
Comments: 16.09.2010
Translation: 0x0415 0x04e2

Generik.DOFLZKJ also known as:

LionicTrojan.Win32.ChePro.4!c
McAfeeRDN/PWS-Banker
CylanceUnsafe
ZillyaTrojan.ChePro.Win32.7787
SangforTrojan.Win32.ChePro.mlbz
AlibabaTrojanBanker:Win32/ChePro.d60b12fc
BitDefenderThetaGen:NN.ZelphiF.34062.pmKfayGcpmnG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DOFLZKJ
KasperskyTrojan-Banker.Win32.ChePro.mlbz
NANO-AntivirusTrojan.Win32.ChePro.dvuevg
AvastWin32:Malware-gen
SophosMal/Generic-R
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.dc
JiangminTrojan/Banker.ChePro.ddh
WebrootW32.Trojan.Gen
AviraTR/Spy.Banker.261120.3
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.130A517
KingsoftWin32.Troj.Generic.v.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C2158599
VBA32TScope.Trojan.Delf
APEXMalicious
TencentWin32.Trojan.Spy.Hvsr
YandexTrojan.PWS.ChePro!T7XzUcBJexI
IkarusTrojan.Spy.Banker
MaxSecureTrojan.Malware.11973.susgen
FortinetW32/ChePro.MLBZ!tr
AVGWin32:Malware-gen
PandaGeneric Suspicious

How to remove Generik.DOFLZKJ?

Generik.DOFLZKJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment