Malware

Generik.KFQUKBD (file analysis)

Malware Removal

The Generik.KFQUKBD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KFQUKBD virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
swqfsfasdfsdfa.ddns.net

How to determine Generik.KFQUKBD?


File Info:

crc32: C6209765
md5: f82b86d54d8fe1d7b012c7353bd37e56
name: F82B86D54D8FE1D7B012C7353BD37E56.mlw
sha1: 2989556e802d4263b63b189b2d8738bf27334186
sha256: 6fa420950e5771fe9612a3ed7267e1670f5032600018a9ee8cb3fa31e14bda2d
sha512: 698d952904fa822a995894b7ffad53eb82dc504ad7d411cabd0b89b53dc0fc0ccb3ecb27f738f03c429045881559b4f1b75624511742682dc9a8cff674ee616f
ssdeep: 12288:UxmIJQvPkitDCR3prQTcw5gpCRu7j6sUPxvySeEIuVWW36ADViEoKP0:KmoO8itDsZcTn8qsUPFySeEIuUWKmIe8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.KFQUKBD also known as:

K7AntiVirusTrojan ( 0052f7b11 )
LionicTrojan.Win32.Generic.4!c
DrWebBackDoor.Tordev.976
ClamAVWin.Malware.Rasftuby-7101804-0
ALYacTrojan.Rasftuby.Gen.14
MalwarebytesMalware.AI.4236826339
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0052f7b11 )
Cybereasonmalicious.54d8fe
CyrenW32/S-e8958863!Eldorado
SymantecRansom.Wannacry
ESET-NOD32a variant of Generik.KFQUKBD
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.Rasftuby.Gen.14
NANO-AntivirusTrojan.Win32.Tordev.favtap
MicroWorld-eScanTrojan.Rasftuby.Gen.14
TencentWin32.Trojan.Generic.Ecad
Ad-AwareTrojan.Rasftuby.Gen.14
ComodoMalware@#2lrqr8jqzwwed
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.f82b86d54d8fe1d7
EmsisoftTrojan.Rasftuby.Gen.14 (B)
AviraTR/Rasftuby.dhtfs
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Rasftuby.Gen.14
McAfeeArtemis!F82B86D54D8F
MAXmalware (ai score=97)
VBA32Backdoor.Tordev
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CDM21
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generik.KFQUKBD?

Generik.KFQUKBD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment