Malware

Generik.KOAUCGM information

Malware Removal

The Generik.KOAUCGM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KOAUCGM virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
ggteam2024.gnway.cc
ip2.nwt.gg-team.net
love2024.vicp.cc
a.tomx.xyz

How to determine Generik.KOAUCGM?


File Info:

crc32: 6BE53FB5
md5: 06a2c36bce309fa089a24b540f73a765
name: 06A2C36BCE309FA089A24B540F73A765.mlw
sha1: 1b0d723580db8e9ec473beb58c6c5a91682f2337
sha256: 463ea7a64c4a27979bcf30c5f2b24b83c70fe356991e3760bf0cf4a8e37924ab
sha512: 4fe8e8b28c49cd0906112052b4479f1703fcffa43698a0bdcbbfe59c1f31bfe235d9f30194649b5ff013593cde84775b7dedf291c59b3ec99169ca23fe4b3f07
ssdeep: 6144:2BDHmrz4niNy8o3Zp/TWt+g4RQTDUBO8/2vh+ziDV8m56TBac2Gu0:wDHmoniNy8L8g4RgoBO8/2vhDX56TX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Microsoft Corporation. All rights reserved.
InternalName:
FileVersion: 2.3.1.0
CompanyName: Microsoft Corporation
LegalTrademarks:
ProductName:
ProductVersion: 2.3.1.0
FileDescription: Microsoft .NET Framework 2.3.1.0
OriginalFilename:
Translation: 0x0409 0x04e4

Generik.KOAUCGM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.21631
ClamAVWin.Keylogger.Delf-9629510-0
ALYacGen:Trojan.Keylogger.ZG3@aaCHNQcj
MalwarebytesTrojan.Crypt
ZillyaTrojan.Delf.Win32.121059
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ymacco.345
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.bce309
BaiduWin32.Trojan.Delf.ae
CyrenW32/Delf.XFNF-6995
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KOAUCGM
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Trojan.Keylogger.ZG3@aaCHNQcj
NANO-AntivirusTrojan.Win32.Delf.hlqubu
MicroWorld-eScanGen:Trojan.Keylogger.ZG3@aaCHNQcj
TencentMalware.Win32.Gencirc.10b9c4c1
Ad-AwareGen:Trojan.Keylogger.ZG3@aaCHNQcj
SophosMal/Generic-R + Mal/SpyAgent-F
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
BitDefenderThetaAI:Packer.4899FE9C1C
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PFG21
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
FireEyeGeneric.mg.06a2c36bce309fa0
EmsisoftGen:Trojan.Keylogger.ZG3@aaCHNQcj (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ezuqc
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan/Generic.ASMalwS.BBB0DE
MicrosoftTrojan:Win32/Ymacco.AA63
GDataGen:Trojan.Keylogger.ZG3@aaCHNQcj
AhnLab-V3Backdoor/Win32.Agent.R115864
McAfeeGenericRXLT-DC!06A2C36BCE30
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PFG21
RisingTrojan.Delf!1.6515 (CLASSIC)
YandexTrojan.Delf!JfpIl4D2VlE
IkarusTrojan-Spy.Win32.Dibik
FortinetW32/Delf.NWT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.KOAUCGM?

Generik.KOAUCGM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment