Malware

What is “Generik.FAUBJLH”?

Malware Removal

The Generik.FAUBJLH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.FAUBJLH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system

Related domains:

silistreturizm.com
ftp.silistreturizm.com

How to determine Generik.FAUBJLH?


File Info:

name: 1D412C1C108C67791E66.mlw
path: /opt/CAPEv2/storage/binaries/5e4d3b3314100a747d3ae6c3e1a5a2ffd9c3545aaf41b8a0c2d274253d6d1608
crc32: 9168AB79
md5: 1d412c1c108c67791e66a5494046f57d
sha1: 9814074e21d817a91ec8d877318977ad93deac35
sha256: 5e4d3b3314100a747d3ae6c3e1a5a2ffd9c3545aaf41b8a0c2d274253d6d1608
sha512: ebafecf0d5d1875a7c8139b6bd21b219d0f1af8182e58b21ce879c72f61279e19dbadcd098517c7a28f55c416008b595c7969079ae7a97d3390947017f3c1f96
ssdeep: 1536:kRx/k/TJhj+hUO46ZIiu+PTPtsUIiu+PTPt5I2u+PTPtTYI:cFoT/yhIP+PJsUIP+PJ5I7+PJTYI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126A3060CDEB84790D2FADB780920D0F07FFEA937E752D66B3D1700B95B62A108E51A56
sha3_384: 6edc4021de7a1dbf62044b6eb973e51679ff503a6cc4be6c74d4df1c7973fe7fa6eb4bb9ffc3953fb70a89adce91e226
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-08-27 21:00:18

Version Info:

Translation: 0x0000 0x04b0
Comments: FPS Optimizesi
CompanyName: Uzayadamı
FileDescription: FPSArttirma
FileVersion: 1.0.0.1
InternalName: Resources Kullanımı.exe
LegalCopyright: Copyright © Uzayadamı
LegalTrademarks: Uzayadamı / Oğuzhansun
OriginalFilename: Resources Kullanımı.exe
ProductName: Uzayadamı
ProductVersion: 1.0.0.1
Assembly Version: 1.0.0.1

Generik.FAUBJLH also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.30843592
FireEyeTrojan.GenericKD.30843592
McAfeeArtemis!1D412C1C108C
CylanceUnsafe
SangforTrojan.Win32.Malware.gen
Cybereasonmalicious.c108c6
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.FAUBJLH
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.30843592
AvastWin32:Malware-gen
TencentWin32.Trojan.Ursu.Dzkb
Ad-AwareTrojan.GenericKD.30843592
EmsisoftTrojan.GenericKD.30843592 (B)
ComodoMalware@#2db11cdni9bcv
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
SophosMal/Generic-S
IkarusTrojan.ATRAPS
GDataTrojan.GenericKD.30843592
MAXmalware (ai score=89)
MicrosoftBackdoor:Win32/Bladabindi!ml
BitDefenderThetaGen:NN.ZemsilF.34294.gm0@aWMKQGp
ALYacTrojan.GenericKD.30843592
TrendMicro-HouseCallTROJ_GEN.R002H0CIG21
YandexTrojan.Agent!YAxzs3jaDcc
SentinelOneStatic AI – Suspicious PE
FortinetGenerik.FAUBJLH!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generik.FAUBJLH?

Generik.FAUBJLH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment