Malware

Generik.KHQKYWX (file analysis)

Malware Removal

The Generik.KHQKYWX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KHQKYWX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
i.imgur.com

How to determine Generik.KHQKYWX?


File Info:

crc32: F05A9179
md5: 91be72060585e65c83a92551276b26f1
name: 91BE72060585E65C83A92551276B26F1.mlw
sha1: 75b1e7b125f441e2c241d1433414b374966b31d4
sha256: 22e14a00dc576e766179076be3199fc04c28fa52fb74f5ba0a9692fbd742a3c0
sha512: 952af839cce5749910bc8785349f0d9fe15611d2f824447547f522a88a93f15cb2962c0081eb775fc1f3092cbd261b272e932af8f65be475cd6c16ad2b80f368
ssdeep: 24576:JUjz3YfDZu1y4yy1bj13DmyUhZaWMzsA8tLpwYxh:JUjuSbQ3fSItL
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generik.KHQKYWX also known as:

Qihoo-360Win32/Trojan.Exploit.7ee
McAfeeArtemis!91BE72060585
AegisLabTrojan.Multi.Generic.4!c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KHQKYWX
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
DrWebBackDoor.Rat.281
McAfee-GW-EditionArtemis!Trojan
IkarusWin32.Outbreak
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.Kryptik.D8WGD3
FortinetW32/Rugmi.FAH!tr.dldr
AVGFileRepMalware

How to remove Generik.KHQKYWX?

Generik.KHQKYWX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment