Malware

About “Generik.KFJFABT” infection

Malware Removal

The Generik.KFJFABT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KFJFABT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.KFJFABT?


File Info:

crc32: F4319594
md5: c867968c707ae487f65eba34f3b03bce
name: C867968C707AE487F65EBA34F3B03BCE.mlw
sha1: 5818b0255a01c7c2bd338a2ced1440f0ba1fd215
sha256: a5947bd0504e1f590af1448a25877ac25bddaf1353851fd9fce2c4d605989002
sha512: 22d64ca578d3afcae3bb651f7ea28f0c1a92f987527c2ec453acdb40fb9393b584aeaa4261d4b486e4eb02eb5d581b00bc8cf2bb4551e7167264f011541cc1ee
ssdeep: 24576:cykfjak4Kk4Bk4OI2gxknk4eNcc2gxk1OPGdOYvrk4w0c31k4:9k4Kk4Bk4XGk4e5uOetk4wXFk4
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 5.8.0.0
InternalName: agent.exe
FileVersion: 5.8.0.0
ProductVersion: 5.8.0.0
FileDescription: AgentTray for DataBackup
OriginalFilename: agent.exe

Generik.KFJFABT also known as:

K7AntiVirusTrojan ( 0052fa6d1 )
CylanceUnsafe
SangforRansom.Win32.REntS.1
AlibabaTrojan:Win32/Fareit.71f39c9a
K7GWTrojan ( 0052fa6d1 )
Cybereasonmalicious.c707ae
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.KFJFABT
APEXMalicious
AvastWin32:Fareit-MB [Trj]
BitDefenderGen:Heur.Ransom.HiddenTears.1
NANO-AntivirusTrojan.Win32.Fareit.fdyteo
MicroWorld-eScanGen:Heur.Ransom.HiddenTears.1
TencentWin32.Trojan.Psw.Syrn
Ad-AwareGen:Heur.Ransom.HiddenTears.1
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXFP-YA!C867968C707A
FireEyeGen:Heur.Ransom.HiddenTears.1
EmsisoftGen:Heur.Ransom.HiddenTears.1 (B)
AviraTR/PSW.Fareit.nflan
Antiy-AVLTrojan/Generic.ASMalwS.25F2A62
MicrosoftTrojan:Win32/Occamy.B
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Heur.Ransom.HiddenTears.1
McAfeeGenericRXFP-YA!C867968C707A
MAXmalware (ai score=95)
PandaTrj/GdSda.A
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Fareit-MB [Trj]
Paloaltogeneric.ml

How to remove Generik.KFJFABT?

Generik.KFJFABT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment