Malware

About “Generik.EKLTMKI” infection

Malware Removal

The Generik.EKLTMKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EKLTMKI virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.EKLTMKI?


File Info:

crc32: 9CC606E2
md5: 57073c95cb15e39905927c1cc8b440ec
name: 57073C95CB15E39905927C1CC8B440EC.mlw
sha1: 661c34140efe716c8f20c61340bb600bbaae286a
sha256: b724f1443c227d09932c99b13fe2e2e6b2be40618aeb8926dad8cfc7571d186a
sha512: 8ec599f90932589951cd293590264b26c524256b063f28161ef80476bac5f853c10bdfe8fd8dba26837344a9c0583bb8b1e9d8e4c8ad2874ce668764ce9847b1
ssdeep: 96:EaZd9w/IoxrmwOyzhOnmtjuD79DWl8A4bKKmVLl+bcV/pt88nyAgzNt:EaZd9w/7NmwOUSYA9SRzlJc7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: x41ax43ex43fx438x440x430x439x442
Assembly Version: 1.0.0.0
InternalName: start.exe
FileVersion: 1.0.0.0
CompanyName: x418x43cx44f x43ax43ex43cx43fx430x43dx438x438
LegalTrademarks: x422x43ex432x430x440x43dx44bx439 x437x43dx430x43a
Comments: x41ax43ex43cx435x43dx442x430x440x438x439
ProductName: x418x43cx44f x43fx440x43ex434x443x43ax442x430
ProductVersion: 1.0.0.0
FileDescription: x41ex43fx438x441x430x43dx438x435 x444x430x439x43bx430
OriginalFilename: start.exe

Generik.EKLTMKI also known as:

LionicTrojan.Win32.Samas.4!c
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.Samas.9
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Application/SuspectCRC.39911088
Cybereasonmalicious.5cb15e
SymantecTrojan Horse
ESET-NOD32a variant of Generik.EKLTMKI
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ransom.Samas.9
NANO-AntivirusTrojan.Win32.Ransom.ffeuam
MicroWorld-eScanGen:Variant.Ransom.Samas.9
TencentWin32.Trojan.Dropper.Stkh
Ad-AwareGen:Variant.Ransom.Samas.9
SophosMal/Generic-S
ComodoMalware@#13ycj2jluu9jd
BitDefenderThetaGen:NN.ZemsilF.34790.am0@ai!WTTc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.57073c95cb15e399
EmsisoftGen:Variant.Ransom.Samas.9 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ransom.Samas.9
McAfeeArtemis!57073C95CB15
MAXmalware (ai score=95)
PandaTrj/GdSda.A
YandexTrojan.Agent!A3dRWNLN22E
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HgIASRIA

How to remove Generik.EKLTMKI?

Generik.EKLTMKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment