Malware

Generik.KRHBHTF malicious file

Malware Removal

The Generik.KRHBHTF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KRHBHTF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • CAPE detected the DCRat malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key

How to determine Generik.KRHBHTF?


File Info:

name: A0BF412D14C79554BF57.mlw
path: /opt/CAPEv2/storage/binaries/f8077d2d27cab4a503603fb6a8836926d7254caff15d16b32547e3cf1341983b
crc32: C5150FB2
md5: a0bf412d14c79554bf579dc817fa1046
sha1: 078a776d930b615607780bf8366966a6049a04c7
sha256: f8077d2d27cab4a503603fb6a8836926d7254caff15d16b32547e3cf1341983b
sha512: dd8e1f6ecbecb64c40f65426b2850fdbcc6d174085480ad4318208c927c0dc1583824413f7afd29950d477b2702cbe0b5d277a305a9f29fd13c59a66f590df97
ssdeep: 98304:mE4/atpigmabX99T67QCerPpaPEklPRLbfzbkndtZfo6J7:j4GX97G7mpXefULZp7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1063301BA75D2F3DB38C97235558B165EBCBD621304EE4BB38CB88CB6715D06A24F26
sha3_384: bf9673a9aba338dbc35a97cde2473782f6fdfabed275f4c123618bf18b2e76ebcbb645b8f79ea6e5b4ba9e002378aa97
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Generik.KRHBHTF also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.4622
CynetMalicious (score: 100)
FireEyeGeneric.mg.a0bf412d14c79554
McAfeeArtemis!A0BF412D14C7
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanPSW:Win32/Stealer.64347382
BitDefenderThetaGen:NN.ZexaF.34084.yF0@aSe80ak
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.KRHBHTF
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Stealer.xuw
BitDefenderTrojan.GenericKD.47635132
MicroWorld-eScanTrojan.GenericKD.47635132
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47635132
EmsisoftTrojan.GenericKD.47635132 (B)
ZillyaTrojan.Agent.Win32.2205396
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S
GDataTrojan.GenericKD.47635132
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R419630
ALYacTrojan.GenericKD.47635132
MAXmalware (ai score=88)
MalwarebytesSpyware.PasswordStealer
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:TrtQ/mVjh0UFhyBxzHzmxQ)
SentinelOneStatic AI – Malicious SFX
eGambitUnsafe.AI_Score_74%
FortinetW32/GenKryptik.FHEB!tr
AVGWin32:Malware-gen
Cybereasonmalicious.d930b6
PandaTrj/CI.A

How to remove Generik.KRHBHTF?

Generik.KRHBHTF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment