Categories: Malware

What is “Generik.EFJWNQS”?

The Generik.EFJWNQS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EFJWNQS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
bnvtfhdfsasd.ug
a.tomx.xyz

How to determine Generik.EFJWNQS?


File Info:

crc32: 0E82F1A4md5: f4d01301bbcb103e352add884aee082aname: asdfg.exesha1: 99f39db2eca3576e6f19b294b9ac16b80423e4c1sha256: 5459853dee95ac5619cf480d85091fd966b9e803fcfd3fa3657867fc5cf8bf3dsha512: c749589423b2e37e4edcad908d9b51e58b8ef0f79e59e542b1a58f191258341005b86728228b70d2b912c4327914cc58c70641d5486f2c284fbddb6c651b9874ssdeep: 24576:IVoVInfIjIpXcz+nasMZsXlh94r0wdtqASOO:koinvpMz+aBsHON0bdtype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: CCopyright (C) 2009-2016 Apple Inc. All Rights Reserved.Assembly Version: 11.9.0.0InternalName: LYyGFWZUdQbgNe.exeFileVersion: 11.9.0.0CompanyName: Apple Inc.LegalTrademarks: Comments: CoreLSKDProductName: CoreLSKDProductVersion: 11.9.0.0FileDescription: CoreLSKDOriginalFilename: LYyGFWZUdQbgNe.exe

Generik.EFJWNQS also known as:

MicroWorld-eScan Trojan.GenericKD.42875537
Qihoo-360 Generic/Trojan.PSW.374
McAfee Artemis!F4D01301BBCB
BitDefender Trojan.GenericKD.42875537
CrowdStrike win/malicious_confidence_80% (W)
F-Prot W32/MSIL_Kryptik.AJV.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Paloalto generic.ml
GData Trojan.GenericKD.42875537
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/Agensla.01f4b8b4
ViRobot Trojan.Win32.Z.Agent.1085952.A
AegisLab Trojan.MSIL.Agensla.i!c
Rising Malware.Undefined!8.C (CLOUD)
Ad-Aware Trojan.GenericKD.42875537
Emsisoft Trojan.GenericKD.42875537 (B)
DrWeb Trojan.Siggen9.23453
McAfee-GW-Edition BehavesLike.Win32.Generic.th
Trapmine malicious.high.ml.score
FireEye Generic.mg.f4d01301bbcb103e
Sophos Mal/Generic-S
Cyren W32/Trojan.TYGC-8604
Webroot W32.Trojan.Gen
Antiy-AVL Trojan[PSW]/MSIL.Agensla
Endgame malicious (high confidence)
Arcabit Trojan.Generic.D28E3A91
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:Win32/Occamy.C
BitDefenderTheta Gen:NN.ZemsilF.34100.cn0@aGArpSj
ALYac Trojan.GenericKD.42875537
MAX malware (ai score=83)
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/GdSda.A
ESET-NOD32 a variant of Generik.EFJWNQS
TrendMicro-HouseCall TROJ_GEN.R011H0CCN20
Tencent Msil.Trojan-qqpass.Qqrob.Eeqq
Ikarus Trojan.SuspectCRC
Fortinet PossibleThreat
AVG Win32:RATX-gen [Trj]
Cybereason malicious.2eca35
Avast Win32:RATX-gen [Trj]

How to remove Generik.EFJWNQS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Jalapeno.2990”?

The Jalapeno.2990 is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Generic.Dacic.1370.2522AF06 removal

The Generic.Dacic.1370.2522AF06 is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago

About “Malware.AI.299088769” infection

The Malware.AI.299088769 is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

About “Malware.AI.4098582889” infection

The Malware.AI.4098582889 is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Backdoor:Win32/Subseven.2_1 information

The Backdoor:Win32/Subseven.2_1 is considered dangerous by lots of security experts. When this infection is active,…

45 mins ago

Marsilia.4611 removal tips

The Marsilia.4611 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago