Malware

How to remove “Generik.KERSSAX”?

Malware Removal

The Generik.KERSSAX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KERSSAX virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Generik.KERSSAX?


File Info:

name: 2955054E2F9C64786049.mlw
path: /opt/CAPEv2/storage/binaries/cd4b90da2dc49dece1b1a4696cfc23bf6fefb37170de9f9b00a3fa11e985bbbc
crc32: BE30344F
md5: 2955054e2f9c64786049d3a029d4c779
sha1: 026131b4ee2d68aff6b734fc3e2dcc60ded49efd
sha256: cd4b90da2dc49dece1b1a4696cfc23bf6fefb37170de9f9b00a3fa11e985bbbc
sha512: 6dd8ad30b5b14ac1ac541dd9ec2277f32ae4a6a5b3e7c6442e70432694f36afba7bf7b6d738f68be87c6fa8d8401c21c136ee191cb56cbca0f44f660f17649be
ssdeep: 3072:B9rwPGmSilMur3j9DM0CSr+Rk0CEQBIUrkmBhy6NJ8Z4PXj4Cp:z5mS1MY042JJ4Cp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188E39E01F2C2C0B1E9F3157915B1E260DF3DF93486ED5DAF6BD40FAA0F211A0D62996A
sha3_384: b594a310d69fb0e2fca16d548e98bc1d47e98c87f070dbce22e1e333d3f8d97202fe748549d1e5bf0142327f6c3487d8
ep_bytes: e8a3020000e97afeffff558bec8b4508
timestamp: 2023-08-25 17:46:41

Version Info:

0: [No Data]

Generik.KERSSAX also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealerc.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68947607
FireEyeGeneric.mg.2955054e2f9c6478
McAfeeArtemis!2955054E2F9C
Cylanceunsafe
SangforInfostealer.Win32.Agent.V7v8
K7AntiVirusTrojan ( 005aa5331 )
K7GWTrojan ( 005aa5331 )
Cybereasonmalicious.4ee2d6
BitDefenderThetaGen:NN.ZexaF.36350.iuX@aGQIIWki
CyrenW32/ABRisk.STEC-4969
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KERSSAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefenderTrojan.GenericKD.68947607
AvastWin32:Evo-gen [Trj]
EmsisoftTrojan.GenericKD.68947607 (B)
F-SecureTrojan.TR/Redcap.btvag
DrWebTrojan.PWS.Stealer.37347
McAfee-GW-EditionBehavesLike.Win32.Infected.ch
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.68947607
JiangminTrojan.PSW.Stealerc.bw
AviraTR/Redcap.btvag
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.R600981
VBA32BScope.TrojanPSW.Stealerc
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1534467915
RisingTrojan.Generic@AI.93 (RDML:NYVVP11U0qS3TLeDrqJvKA)
IkarusWin32.Outbreak
FortinetW32/Kryptik.0A1A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generik.KERSSAX?

Generik.KERSSAX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment