Malware

Generik.KTGIWEY removal

Malware Removal

The Generik.KTGIWEY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KTGIWEY virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.KTGIWEY?


File Info:

crc32: C8F86960
md5: 19f36f566b132a78e1322f663f344f05
name: upload_file
sha1: 9aaf77fccdb21de9cbec2f85ef76f9363e0cc161
sha256: 44b25fc20a9882affa7a9623543e7e7f36da01aa874ac3acb670592031dcc9bc
sha512: 20d8c4117bd96f4fc142065dbebd439f9799e590e8efac34e74c7a93d9e5ede0dd81a7bf08850bee35dbcb2c8db7b9fbad40a754f7e3ae531dd7229e0f430e95
ssdeep: 192:wfRb5ENslLZEvA+6/6rrILd/Kf3HO8tzOSePVLKmqhxytUs6ay0juItcSqt0U3a:wZ5x8iSUR/8dzOXeoB6ay0jLtWKU3a
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: ADMIN, Template: Normal, Last Saved By: ADMIN, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Jun 7 12:21:00 2019, Last Saved Time/Date: Fri Jun 7 12:21:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 0, Security: 0

Version Info:

0: [No Data]

Generik.KTGIWEY also known as:

CAT-QuickHealW97M.Downloader.36753
McAfeeRDN/Generic Downloader.x
VIPRELooksLike.Macro.Malware.k (v)
SangforMalware
F-ProtNew or modified W97M/Downldr
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.KTGIWEY
AvastVBA:Downloader-FWH [Trj]
ClamAVDoc.Dropper.Agent-6993785-0
KasperskyHEUR:Trojan.Script.Generic
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
AegisLabTrojan.Script.Generic.4!c
TencentHeur.Macro.Generic.a.33a79416
Endgamemalicious (high confidence)
ComodoMalware@#1rpe3n51o9pu7
F-SecureMalware.W97M/Agent.6393727
DrWebTrojan.DownLoader28.43802
McAfee-GW-EditionBehavesLike.Downloader.nx
IkarusTrojan-Downloader.Script
CyrenW97M/Downldr
AviraW97M/Agent.6393727
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ml
ArcabitHEUR.VBA.Trojan.e
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
MicrosoftTrojanDownloader:O97M/Dornoe.A!rfn
TACHYONSuspicious/W97M.Obfus.Gen.8
ZonerProbably Heur.W97Obfuscated
RisingDownloader.Certutil/VBA!1.B859 (CLASSIC)
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.TLR!tr.dldr
AVGVBA:Downloader-FWH [Trj]
Qihoo-360virus.office.qexvmc.1065

How to remove Generik.KTGIWEY?

Generik.KTGIWEY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment