Malware

Generik.KAOICVS removal tips

Malware Removal

The Generik.KAOICVS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KAOICVS virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.KAOICVS?


File Info:

name: 5A8DC7F42382940DE579.mlw
path: /opt/CAPEv2/storage/binaries/7efed77fce8b62daec701fd64742de33956b33dc8384e154c4172bf83f71212e
crc32: D8F2CAD1
md5: 5a8dc7f42382940de5795218421e6e3e
sha1: e2923aed6c32f70690509e73900570116ffe388c
sha256: 7efed77fce8b62daec701fd64742de33956b33dc8384e154c4172bf83f71212e
sha512: b7664b8e424f0c1d1def91161cdd69b1af61158ee089062d72702dc18d6e76247e4608f0f1819f87885e3eeddf12811c7d8f967f33c4181a0a1d0146cc81aa27
ssdeep: 24576:pwWHhK2FjW8WVKORtqRJvJ/EtADPudymKFaU3b9Z+1RS6mPPAJjI5X:aWHhKejW8gKkeOtADPzAU3BZ+TQPPL5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105352336DBDD13A9E5F341B785BF29C07E74DAB08C1B7B053196F8B80C3A2506216E62
sha3_384: 49f91bcf225344f12b37a71ce7942c3fe7d3019163459a0a700da8e2b5ae9e9891a518bc8a6ceb197ca5dd2827ef134c
ep_bytes: 60be001046008dbe0000faff5783cdff
timestamp: 2016-11-28 10:27:53

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileVersion: 15.0.23.0
LegalCopyright: Copyright 2016 Avira Operations GmbH & Co. KG. All rights reserved.
OriginalFilename: MailGuard_POP3.exe
ProductName: Avira Swat Apl Rs
ProductVersion: 15.0.23.0
Translation: 0x0809 0x04b0

Generik.KAOICVS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ramy.4!c
MicroWorld-eScanAIT.Heur.Ramy.1.B285E6D2.Gen
FireEyeAIT.Heur.Ramy.1.B285E6D2.Gen
CAT-QuickHealTrojan.Autcobit
ALYacAIT.Heur.Ramy.1.B285E6D2.Gen
MalwarebytesGeneric.Malware.AI.DDS
VIPREAIT.Heur.Ramy.1.B285E6D2.Gen
SangforTrojan.Win32.Autcobit.Vkbt
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutCobit.2955b4e6
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.KAOICVS
APEXMalicious
ClamAVWin.Malware.Autoit-6992293-0
BitDefenderAIT.Heur.Ramy.1.B285E6D2.Gen
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Autcobit.Bujl
EmsisoftAIT.Heur.Ramy.1.B285E6D2.Gen (B)
F-SecureTrojan.TR/AutCobit.mcfki
DrWebTrojan.BtcMine.1084
TrendMicroTROJ_GEN.R002C0DGS23
McAfee-GW-EditionBehavesLike.Win32.DLSponsor.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.CDL9ON
GoogleDetected
AviraTR/AutCobit.mcfki
Antiy-AVLHackTool/Win32.Agent
ArcabitAIT.Heur.Ramy.1.B285E6D2.Gen [many]
MicrosoftTrojan:Win32/AutCobit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nymeria.C2495045
McAfeeArtemis!5A8DC7F42382
MAXmalware (ai score=87)
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DGS23
RisingTrojan.Generic@AI.95 (RDML:tJAwHU/ip967qOQYJpdMhA)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.215134811.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generik.KAOICVS?

Generik.KAOICVS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment