Malware

What is “Generik.KIDWNPB”?

Malware Removal

The Generik.KIDWNPB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KIDWNPB virus can do?

  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

Related domains:

crl.verisign.com

How to determine Generik.KIDWNPB?


File Info:

name: C4466BD9DA572A207F11.mlw
path: /opt/CAPEv2/storage/binaries/5bd3d9b3eb43b2b43738d9e1afdd2701938fc63fd17524670dbd8644a3a63da1
crc32: 6264429F
md5: c4466bd9da572a207f11cb5ccc59c239
sha1: 5e5e5525e03877aa4b1c878c4dbf84519cca7d89
sha256: 5bd3d9b3eb43b2b43738d9e1afdd2701938fc63fd17524670dbd8644a3a63da1
sha512: df82a732cffcc12467ddfb2b0ad7fdf96e3bd4bad2eb09d5e3514c47d1409cc2dba160bcfdcbfced7cb496e5e44d0070a461943b4d6dc47d4d5f063a527c32c4
ssdeep: 24576:htkKs/0c/mdgFN0kzT2uAsStEFB/Bpn3A5xzyeGWtGUAOGYQyesM:fk7McuuFGA+y3SF3UUlGYQbV
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1A865D0F86140735CC81E88609033ED19E1B1125E07FAD9EB76D7BAA07FE74E1A631B49
sha3_384: 271804a44fabed4040622468204e5cd19221dcc98e2358f4296f614038098f35601c94a3f73b15b5f50d171c81e59a87
ep_bytes: 48895c2408574883ec20488bda488bf9
timestamp: 2021-03-17 07:26:52

Version Info:

0: [No Data]

Generik.KIDWNPB also known as:

LionicTrojan.Win64.Agent.5!c
MicroWorld-eScanTrojan.GenericKD.37911210
FireEyeGeneric.mg.c4466bd9da572a20
ALYacTrojan.GenericKD.37911210
CylanceUnsafe
ZillyaRootkit.Agent.Win64.778
SangforRootkit.Win64.Agent.gen
AlibabaRootkit:Win64/RootkitAgent.3aad282d
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.KIDWNPB
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Rootkit.Win64.Agent.gen
BitDefenderTrojan.GenericKD.37911210
NANO-AntivirusTrojan.Win64.Mlw.iuywvy
AvastWin64:Malware-gen
Ad-AwareTrojan.GenericKD.37911210
EmsisoftTrojan.GenericKD.37911210 (B)
DrWebTrojan.Rootkit.22078
TrendMicroTROJ_GEN.R002C0WK221
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S (PUA)
GDataTrojan.GenericKD.37911210
JiangminRootkit.Agent.rvu
AviraRKIT/Agent.lckub
Antiy-AVLTrojan/Generic.ASMalwS.3257E21
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!C4466BD9DA57
MAXmalware (ai score=85)
VBA32Rootkit.Win64.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0WK221
RisingTrojan.MalCert!1.BE29 (CLASSIC)
YandexRootkit.Agent!C8NqANZ9csA
IkarusRootkitAgent
MaxSecureTrojan.Malware.74230818.susgen
FortinetW64/Agent!tr.rkit
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Generik.KIDWNPB?

Generik.KIDWNPB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment