Malware

How to remove “Generik.KFJESNC”?

Malware Removal

The Generik.KFJESNC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KFJESNC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.KFJESNC?


File Info:

crc32: CEBC8310
md5: 668553a5be6db4112e48dc514bf94952
name: 668553A5BE6DB4112E48DC514BF94952.mlw
sha1: 32dfc0849f951443587389f988e3367bd0af9796
sha256: 966d93cd501df4b32a9d9e11f1d5612832e90c7c186c7a15da46112dfa9a1487
sha512: a302b92ceefcacb5b605ed239cdeb229115459822895a18ba000ec7e45c3b0a3ed71196663689b3175ccc10a6ece17bfe152a65ef0e550caed44ce8cd714fc9a
ssdeep: 98304:wE+RVox2wjAeS4iyLUWQpBGiegvdolxmjGyxTdVbmwlnY5mv6fYwOmjrer9PJ8d:8HvyupIit7GyBd9nYESYwOmj6dKJwf9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Generik.KFJESNC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36105853
FireEyeGeneric.mg.668553a5be6db411
McAfeeArtemis!668553A5BE6D
CylanceUnsafe
VIPREWin32.Malware!Drop
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005762b31 )
BitDefenderTrojan.GenericKD.36105853
K7GWTrojan ( 005762b31 )
Cybereasonmalicious.49f951
BitDefenderThetaGen:NN.ZexaF.34760.@pKfaOLyGBcG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Eb.bns
AlibabaTrojan:Win32/GoCloudnet.66e4a3fc
RisingTrojan.Kryptik!8.8 (TFE:5:blSGgaexi2K)
Ad-AwareTrojan.GenericKD.36105853
EmsisoftTrojan.GenericKD.36105853 (B)
F-SecureTrojan.TR/AD.GoCloudnet.olerk
TrendMicroTrojanSpy.Win32.OUTBREAK.USMANAF21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.SmokeLoader
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.olerk
MicrosoftTrojan:Win32/Wacatac.D9!ml
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D226EE7D
ZoneAlarmTrojan.Win32.Eb.bns
GDataTrojan.GenericKD.36105853
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4298558
Acronissuspicious
VBA32BScope.Trojan.Zenpak
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.KFJESNC
TrendMicro-HouseCallTrojanSpy.Win32.OUTBREAK.USMANAF21
TencentWin32.Trojan.Eb.Wozt
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.b9b

How to remove Generik.KFJESNC?

Generik.KFJESNC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment