Malware

About “Generik.JULIEEF” infection

Malware Removal

The Generik.JULIEEF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.JULIEEF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates services, possibly for anti-virtualization
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify UAC prompt behavior

How to determine Generik.JULIEEF?


File Info:

name: FBEC7C4E0F825BD0CDBD.mlw
path: /opt/CAPEv2/storage/binaries/eebbc7fafa3357fbd5d8af03ad4b086f7c87afa6f519a243bf7beff4fd174fd6
crc32: 123BFE96
md5: fbec7c4e0f825bd0cdbd3883cef585fe
sha1: 99baefd43aeb34c4a44612049a0446e0e25ef4ba
sha256: eebbc7fafa3357fbd5d8af03ad4b086f7c87afa6f519a243bf7beff4fd174fd6
sha512: 4af1fe1e7cbd49730bad16d65d9a81cc342609ac342d5bbb83206d295cd4313ed3004dae766ebfbf38f2ec739a231efb1a45612c8513d2e816ad316812d49073
ssdeep: 98304:FaLAhHeiuc73Rle0Wy22Dcn2BlJPD8Nzl2fT8mRaw8GFvuztrIcw:6ViuykXEnt8NrLwJ+Uf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E3633EE0279CF27D35C7C39BCB73DA69F649C852E7901A552A23D1429F265FA40CE20
sha3_384: 02cc3e92e102638e367151b1bcf75522ad359468fc85c243aca043bbddb2f71486aa537683a8e884dd79b830710f7ef3
ep_bytes: 60be001093008dbe0000adff57eb0b90
timestamp: 2018-10-08 08:56:30

Version Info:

FileVersion: 2.0.18.8261
ProductVersion: 1.0.0.1822
LegalCopyright: Copyright © 2013-2018
授权方式: arFi
Translation: 0x0804 0x04b0

Generik.JULIEEF also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fbec7c4e0f825bd0
McAfeeArtemis!FBEC7C4E0F82
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.56209
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.8cedfcd5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JULIEEF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Rovnix-6803887-0
KasperskyTrojan-Ransom.Win32.Blocker.llwi
BitDefenderTrojan.GenericKD.42317295
NANO-AntivirusTrojan.Win32.Drop.gzrste
MicroWorld-eScanTrojan.GenericKD.42317295
AvastWin32:Malware-gen
RisingTrojan.Obfus/Autoit!1.D77B (CLASSIC)
SophosMal/Generic-S
DrWebTrojan.MulDrop9.36565
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R002C0DK621
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.GenericKD.42317295 (B)
IkarusTrojan.Blocker
JiangminTrojan.Scar.hm
AviraHEUR/AGEN.1142016
MicrosoftRansom:Win32/Blocker
ZoneAlarmTrojan-Ransom.Win32.Blocker.llwi
GDataTrojan.GenericKD.42317295
AhnLab-V3Malware/Win32.Generic.C4247763
ALYacTrojan.GenericKD.42317295
MAXmalware (ai score=87)
VBA32TrojanRansom.Blocker
MalwarebytesMalware.AI.3345074565
TrendMicro-HouseCallRansom_Blocker.R002C0DK621
TencentWin32.Trojan.Blocker.Ehrw
MaxSecureTrojan.Malware.11913.susgen
FortinetW32/Blocker.LLWI!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e0f825
PandaTrj/CI.A

How to remove Generik.JULIEEF?

Generik.JULIEEF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment