Malware

Should I remove “Generik.JBTMRXH”?

Malware Removal

The Generik.JBTMRXH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.JBTMRXH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.JBTMRXH?


File Info:

crc32: F1CFBEFE
md5: ea8a5f13acc880b604b247864b069aa4
name: EA8A5F13ACC880B604B247864B069AA4.mlw
sha1: 5113636ce26a7cd5165f12a69ac80989aefa679b
sha256: 3fc6bcefbddaebc560931350038d2c9df1ddef8f5585ef89505bad0d3f6c1672
sha512: 36ff63b177eaa9d04ca04f83d0e87aad13fd75585aea4150ace0d8a656cddb279b7aba55f63a01f92c5a6713ea498c2a3be62773c4f976b66baa48a0a3a171f1
ssdeep: 98304:5fahQ5u0CUojULOvlqiNtOg7rwGjv8jsmOtC4bL9ZnBDMdHwssx8MU8wOv3WA4g:5eXkUrD/mwnBaQFQ0LA5G5
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkafude
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00dc

Generik.JBTMRXH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45452687
FireEyeGeneric.mg.ea8a5f13acc880b6
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!EA8A5F13ACC8
CylanceUnsafe
ZillyaTrojan.Eb.Win32.327
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/Predator.b7f474cf
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.CXK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Eb.bnb
BitDefenderTrojan.GenericKD.45452687
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.45452687
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1122056
DrWebTrojan.Siggen11.58300
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.KRYPTIK.USMANAD21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
EmsisoftTrojan.GenericKD.45452687 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122056
Antiy-AVLTrojan/Win32.Generic
MicrosoftPWS:Win32/Predator.KM!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B58D8F
AegisLabHacktool.Win32.ArchSMS.lsxE
ZoneAlarmTrojan.Win32.Eb.bnb
GDataTrojan.GenericKD.45452687
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R362868
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfay8d1SnG
ALYacTrojan.GenericKD.45452687
MAXmalware (ai score=88)
VBA32BScope.Trojan.Caynamer
ESET-NOD32a variant of Generik.JBTMRXH
TrendMicro-HouseCallTrojanSpy.Win32.KRYPTIK.USMANAD21
RisingTrojan.Kryptik!1.D139 (CLASSIC)
IkarusTrojan-Downloader.Win32.SmokeLoader
FortinetW32/Kryptik.HIRY!tr
AVGFileRepMalware
PandaTrj/GdSda.A
Qihoo-360Generic/HEUR/QVM11.1.92FB.Malware.Gen

How to remove Generik.JBTMRXH?

Generik.JBTMRXH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment