Malware

What is “Generik.JETGCOO”?

Malware Removal

The Generik.JETGCOO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.JETGCOO virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • The office file contains 4 macros
  • The office file contains a macro with auto execution
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • The office file contains a macro with suspicious strings

Related domains:

chu576f.com

How to determine Generik.JETGCOO?


File Info:

crc32: 55243886
md5: a80590db1033eeaba2f6c86ab40aca1b
name: upload_file
sha1: 37269f8653f84b5bcffdf2a0466e15cac1df75c9
sha256: 0beef303ce25104d0339c45c9639a79759e016bc38f4b7d9bde2217e3ef00cfe
sha512: 4f9fc020f9a37ff8ac69a57f6e0169a089645c3a383675f5e1d2f21091d50967858215b1e8ee3163a017e97e81caa8135f0c1b91b450b97ebf46a1a95dc038c5
ssdeep: 3072:fd7iFwjUliDjdvK5xgjUpRZ89B7WmW4pQDelNEjoqWUHIk/B3CyN/:GwQliDjdOXpRq9B724pQ6jEXdok/lJ
type: Microsoft Word 2007+

Version Info:

0: [No Data]

Generik.JETGCOO also known as:

Elasticmalicious (high confidence)
AegisLabTrojan.MSWord.Generic.4!c
BitDefenderTrojan.GenericKD.44012903
ArcabitHEUR.VBA.CG.1
CyrenPP97M/Agent.KC.gen!Eldorado
SymantecISB.Downloader!gen428
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
AlibabaTrojanDownloader:VBA/Obfuscation.A
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
MicroWorld-eScanTrojan.GenericKD.44012903
Ad-AwareTrojan.GenericKD.44012903
EmsisoftTrojan.GenericKD.44012903 (B)
F-SecureMalware.VBA/Dldr.Agent.njzdc
TrendMicroHEUR_VBA.O2
McAfee-GW-EditionBehavesLike.Downloader.cc
FireEyeTrojan.GenericKD.44012903
IkarusTrojan-Downloader.VBA.Agent
AviraW97M/Dldr.Agent.dqzgh
MicrosoftTrojanDownloader:O97M/Obfuse.JM!MTB
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan.Agent.8AFYYN
ALYacTrojan.Downloader.DOC.Gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32a variant of Generik.JETGCOO
SentinelOneDFI – Malicious OPENXML
FortinetVBA/Agent.UPE!tr
AVGOther:Malware-gen [Trj]
Qihoo-360virus.office.obfuscated.1

How to remove Generik.JETGCOO?

Generik.JETGCOO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment