Malware

Generik.KSUAFRC information

Malware Removal

The Generik.KSUAFRC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KSUAFRC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Generik.KSUAFRC?


File Info:

name: 192AE9E53CDA10408D49.mlw
path: /opt/CAPEv2/storage/binaries/54bfec43c2943d12e6820666a4061a1d5c63fe5a8cbebc47a226279523428bbc
crc32: A82B0BDB
md5: 192ae9e53cda10408d49f7c4f627a35a
sha1: 5a343d163ba23b004c047a49c09e6767603a827b
sha256: 54bfec43c2943d12e6820666a4061a1d5c63fe5a8cbebc47a226279523428bbc
sha512: ed28c7d3d0bd27d0c9dd3938e32f1de15f19754b301410fe640d776a179d5c71a7e98d6fc2e6277808b75b49bdb74bc717fdf27eab6a836a7c4cc299ab3a9e91
ssdeep: 98304:RLGSThOfTCiFBXmfFs+JMHpCVoR8oMEOJ6Ty3RvX+Y2nb:YBfTCiUswVSLOJgyBG/b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1463362F440E430E039153A15EA48A1F07DBD7187354A8FB39E3B755E392E8257AE8F
sha3_384: 004b005906c1f66a9fceb34182366a81c2b9bfc95965cb1d008f1cfccb1d041bee5e4be9d5d9435d88f8218060b143b7
ep_bytes: e836050000e98efeffffcccccc575653
timestamp: 2018-09-04 14:43:33

Version Info:

0: [No Data]

Generik.KSUAFRC also known as:

LionicTrojan.Win32.Crypren.tpW3
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47491156
McAfeeArtemis!192AE9E53CDA
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Occamy.faedcc12
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.53cda1
CyrenW32/S-f857af78!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KSUAFRC
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.47281292
NANO-AntivirusTrojan.Win32.Crytes.iejucj
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47281292
SophosMal/Generic-R
ComodoWorm.Win32.Bflient.~AD2@3d18gh
DrWebTrojan.BtcMine.3428
TrendMicroTROJ_GEN.R02DC0DL421
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.192ae9e53cda1040
EmsisoftTrojan.GenericKD.47491156 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.6J8F2R
AviraHEUR/AGEN.1134395
GridinsoftRansom.Win32.Occamy.sa
ArcabitTrojan.Generic.D2D4A854
ViRobotTrojan.Win32.Z.Agent.5491712
MicrosoftTrojan:Win32/Occamy.AA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R342010
ALYacTrojan.GenericKD.38219889
MAXmalware (ai score=88)
VBA32Trojan.BtcMine
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R02DC0DL421
IkarusTrojan.Win32.Ymacco
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/GenericKD.4266!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generik.KSUAFRC?

Generik.KSUAFRC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment