Malware

Should I remove “Generik.KHZJPSG”?

Malware Removal

The Generik.KHZJPSG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KHZJPSG virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Generik.KHZJPSG?


File Info:

name: AF56F7FB3F9289288632.mlw
path: /opt/CAPEv2/storage/binaries/b69462ca7f5711b5f2f87e11bed1096000bf130041bff68f40673ed7e7fff3cf
crc32: F9D23C1C
md5: af56f7fb3f928928863235e518100945
sha1: 7ee6d4b45427c38039f617f50a270a697021c869
sha256: b69462ca7f5711b5f2f87e11bed1096000bf130041bff68f40673ed7e7fff3cf
sha512: 9fa03642d7d73caaa115c9979f3cbb3bbded934ac257ce9ea57c5f88bf05fb1a0ab930b02d85595807d4b0c45e61bd2fe72f79172c04bfa9f8b4d50cf83b97a2
ssdeep: 98304:gfYNPjtl7u9pq6lYMZPxoHMjWmrrRaFLwkl5oDeuVf6VWV+:jpTGpHDZPWsx5aKklyDeogZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A462363A36A0142E5978C35E62B7EE531F6072BDF81B87816C7FCC621225D2E217E53
sha3_384: eaceb1919779de4e049213b3cc8c4cf98eb10485aad73e0dda07a0d973d118757e8d96e55d8767219590d3eee5c84804
ep_bytes: 683ac8bd09e8dbb6bdff668946040fc8
timestamp: 1992-06-19 22:22:17

Version Info:

FileVersion: 2.2.0.0
Comments: This application is designed to simplify the DNS changing process.
FileDescription: DNS Jumper v2.2
LegalCopyright: Copyright © 2009 - 2020 www.sordum.org All Rights Reserved.
CompanyName: www.sordum.org
Coder: By BlueLife
Translation: 0x0809 0x04b0

Generik.KHZJPSG also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38457751
McAfeeArtemis!AF56F7FB3F92
CylanceUnsafe
VIPRETrojan.GenericKD.38457751
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056eb701 )
BitDefenderTrojan.GenericKD.38457751
K7GWTrojan ( 0056eb701 )
Cybereasonmalicious.45427c
ArcabitTrojan.Generic.D24AD197
ESET-NOD32a variant of Generik.KHZJPSG
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Delfea.md
AlibabaTrojanDropper:Win32/Delfea.4faf3c27
RisingTrojan.Nanobot!8.80F2 (TFE:5:ODaZsRE2pBC)
Ad-AwareTrojan.GenericKD.38457751
EmsisoftTrojan.GenericKD.38457751 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.af56f7fb3f928928
SophosMal/VMProtBad-A
IkarusTrojan.Win32.VMProtect
JiangminTrojanDropper.Delfea.ai
AviraHEUR/AGEN.1203970
MicrosoftTrojan:Win32/Trickbot!ml
GDataTrojan.GenericKD.38457751
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R424135
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34698.@N0@aa3TJCj
ALYacTrojan.GenericKD.38457751
MAXmalware (ai score=89)
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.1999271584
PandaTrj/CI.A
TencentWin32.Trojan-Dropper.Delfea.Eplw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generik.KHZJPSG?

Generik.KHZJPSG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment