Malware

Generik.JRSCBOS removal tips

Malware Removal

The Generik.JRSCBOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.JRSCBOS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generik.JRSCBOS?


File Info:

crc32: EE45D837
md5: dba3d7f3ca0f9c2d94b4d6830a344c93
name: DBA3D7F3CA0F9C2D94B4D6830A344C93.mlw
sha1: 061757eb4edf849bf231ecd1448d4a04ce2dee81
sha256: 1fb769b269392860ff1951b079f7b8cf4bbe22e09a856e15fbb7a5426aa6a109
sha512: cc24593c24f34993c3c52d74b24543062a52bc1e9fbf022659e5e40b9da2de7b62bc59b68ecc760ce8ab9a4b47785073e48c7bd095d0aceb83b5dd41badfe01b
ssdeep: 12288:q1P5cRa6fzVWQKBtCkXbrUoTMXlNhj3NNQTYic3m1:q1P5c46bVWNrL+Xp3jQTYiKw
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Generik.JRSCBOS also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!DBA3D7F3CA0F
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.36247441
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b4edf8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JRSCBOS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.NanoBot.gen
AlibabaTrojan:Win32/autoit.ali2000008
MicroWorld-eScanTrojan.GenericKD.36247441
Ad-AwareTrojan.GenericKD.36247441
SophosMal/Generic-S
F-SecureTrojan.TR/AD.LokiBot.ajkoe
DrWebTrojan.PWS.Siggen2.59088
TrendMicroBackdoor.Win32.NANOCORE.ODIG
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.dba3d7f3ca0f9c2d
EmsisoftTrojan.GenericKD.36247441 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.LokiBot.ajkoe
MAXmalware (ai score=95)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/CryptInject!ml
ZoneAlarmHEUR:Trojan.Win32.NanoBot.gen
GDataWin32.Trojan-Stealer.LokiBot.D7T9PL
VBA32suspected of VBS.EncodedMalware
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win32.NANOCORE.ODIG
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.BO.2f4

How to remove Generik.JRSCBOS?

Generik.JRSCBOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment