Malware

Generik.KPHDVQA removal tips

Malware Removal

The Generik.KPHDVQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KPHDVQA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Generik.KPHDVQA?


File Info:

name: 232C38D6AFFA4622FB4B.mlw
path: /opt/CAPEv2/storage/binaries/fb515c71611cd8bd6a8c7fa2bed7023f4c84f331a58693d757355aff03299e78
crc32: 68D47B88
md5: 232c38d6affa4622fb4b376e22c0796b
sha1: aa7907193c7e75cb9d03c1a65f956ccdb933107d
sha256: fb515c71611cd8bd6a8c7fa2bed7023f4c84f331a58693d757355aff03299e78
sha512: 1fe557000141629ce0038cae4c61ec460f869ee25443f94cf2fdf8989e4b90e6a0a3ea305e34c67a7b1b2728c11ab21c5bbd74af08519bd513baeea570948ffe
ssdeep: 24576:CoZaA3QP9SX03xSXTYDXmzTUqJmLFci4:naA3QPS03eoqn
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1AE85B60BFBB611C1E5BAC139A553322AFC7134A5873897D792459A0E1BB1BE4ED3E700
sha3_384: 269b51dccf04f8a37d1fcc69c7892354044617d156664a1738fee21df9926eb21b0f36fb1036ebc4f5ad7a0b1921cf6a
ep_bytes: e9b6c70600e971901200e91cb40500e9
timestamp: 2021-11-21 03:09:55

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: FlyStart.exe
LegalCopyright: Copyright (C) 2021
OriginalFilename: FlyStart.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

Generik.KPHDVQA also known as:

LionicTrojan.Win32.Convagent.3!c
MicroWorld-eScanTrojan.GenericKD.47457652
McAfeeArtemis!232C38D6AFFA
ZillyaTrojan.Cobalt.Win32.1464
AlibabaTrojan:Win32/Cobalt.cdd2efba
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.KPHDVQA
TrendMicro-HouseCallTROJ_GEN.R002C0WKN21
KasperskyTrojan.Win32.Cobalt.hcl
BitDefenderTrojan.GenericKD.47457652
AvastWin64:Malware-gen
TencentWin32.Trojan.Cobalt.Hnuy
Ad-AwareTrojan.GenericKD.47457652
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WKN21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.47457652
EmsisoftTrojan.GenericKD.47457652 (B)
JiangminTrojan.Cobalt.nt
AviraTR/Cobalt.hvnmu
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.34C4185
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D2D42574
ViRobotTrojan.Win32.Z.Cobalt.1850880.A
GDataTrojan.GenericKD.47457652
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47457652
APEXMalicious
IkarusTrojan.SuspectCRC
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Generik.KPHDVQA?

Generik.KPHDVQA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment