Malware

Generik.KMKTMCS malicious file

Malware Removal

The Generik.KMKTMCS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KMKTMCS virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generik.KMKTMCS?


File Info:

crc32: CA4B8745
md5: db4d79a0971cbf3747bd9ce169e8cc93
name: DB4D79A0971CBF3747BD9CE169E8CC93.mlw
sha1: 2680b25d0b3cf1573df611c96b6932fd8d1045a8
sha256: 1a34c25f8b76b0e3213f2d58966090778a95264e8960e11ef67e8a9c88b29eb2
sha512: aefa6a0cfea5c3a4a3c3b71c2869d92b9949674af38376f827b76343eb91fa89e889defd7c30b86a2301d12c09dc8e16d78ea8b553970f627fea7db59b599940
ssdeep: 24576:PRIWXmD+Ifp8jYXZE1Q7DLVwjdyX96ZZQQAFFHB7h3pKKGJ:PRIWXQ+tjYRwpwIZzGHBmJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: ATUALIZADORVERSAO
FileVersion: 3.7.0.123
CompanyName: Prefeitura Municipal
LegalTrademarks:
ProductName: Sistema de Gestxe3o Financeira, Orxe7amentxe1ria e Contxe1bil
ProductVersion: 3.7.0.123
FileDescription: Atualizador de Versxe3o
OriginalFilename: ATUALIZADORVERSAO.EXE
BuildDate: 07 agosto, 2018
Translation: 0x0416 0x04e4

Generik.KMKTMCS also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Jacard.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/PolyPatch.b8ec19bd
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.d0b3cf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KMKTMCS
APEXMalicious
AvastWin32:dUmPeX [Susp]
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.67EF9A0319
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.db4d79a0971cbf37
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1111097
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeePolyPatch-UPX
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
YandexTrojan.Agent!MCNpVi46OWs
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PolyPatch.UPX!tr
AVGWin32:dUmPeX [Susp]
Paloaltogeneric.ml

How to remove Generik.KMKTMCS?

Generik.KMKTMCS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment