Malware

Should I remove “Generik.JGUXZGB”?

Malware Removal

The Generik.JGUXZGB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.JGUXZGB virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Generik.JGUXZGB?


File Info:

name: 373DD61E05B03DD75B27.mlw
path: /opt/CAPEv2/storage/binaries/0dec6f4bdc8d74ecfb7a7f94ed131c11df41bb513438666d90be0872e5d98384
crc32: 71D3B92A
md5: 373dd61e05b03dd75b276bc3249d6ad4
sha1: e5a9d2eae2cef43f0132334293fafde8e1074fde
sha256: 0dec6f4bdc8d74ecfb7a7f94ed131c11df41bb513438666d90be0872e5d98384
sha512: 74c7c9d0a0735f183823102d12ed67e1275f210208c09e505ab42b20132d63d25b172ce3a0adaf7f657cb43dcadb042846e30f6e9462dee66caae2d6642f7b25
ssdeep: 49152:mn4vfawdpSSpEOD1oe+Mo1EOQOLxNG9QEXvAzzQRQ4y8:c4vfawfSSB1dVvGnEXoGQj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6E57B11E105802FCAB341794E7E776D619CEF22031566C3A2CC7E1D6BB9EE2B93914E
sha3_384: d8757e0136974cd83d547bf0b6448077857f1fe24d9a141a31f0e5fa3e51e2ece70e04b1b67d33134989851163f55787
ep_bytes: 6810106b00ff153c9a6800e99025e5ff
timestamp: 2055-05-25 18:10:40

Version Info:

CompanyName:
FileDescription: Ebenezer MFC 응용 프로그램
FileVersion: 1, 0, 0, 1
InternalName: Ebenezer
LegalCopyright: Copyright (C) 2001
LegalTrademarks:
OriginalFilename: Ebenezer.EXE
ProductName: Ebenezer 응용 프로그램
ProductVersion: 1, 0, 0, 1
Translation: 0x0412 0x04b0

Generik.JGUXZGB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.373dd61e05b03dd7
McAfeeGenericRXBP-XL!373DD61E05B0
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Occamy.7a9bb689
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Generic.ADGT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.JGUXZGB
APEXMalicious
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.DownLoad3.fnsabc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b4ac65
DrWebTrojan.DownLoad3.10780
ZillyaTrojan.TDSS.Win32.45506
TrendMicroTROJ_GEN.R002C0DGU22
McAfee-GW-EditionGenericRXBP-XL!373DD61E05B0
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
Antiy-AVLTrojan/Win32.AGeneric
ViRobotTrojan.Win32.Z.Graftor.3117056
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34606.!E3@auna@AfH
MalwarebytesMalware.AI.3828133279
TrendMicro-HouseCallTROJ_GEN.R002C0DGU22
RisingWin32.Loader.p (CLASSIC)
YandexTrojan.GenAsa!k2UfqOY3c5I
IkarusWorm.QVod
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.XL!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ae2cef
PandaTrj/CI.A

How to remove Generik.JGUXZGB?

Generik.JGUXZGB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment