Malware

About “Generik.KTZJFBT” infection

Malware Removal

The Generik.KTZJFBT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.KTZJFBT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.KTZJFBT?


File Info:

crc32: A71B9222
md5: ccbca3143707a91c13550ec0d9661cab
name: b32priv.exe
sha1: a3d341c4d9d9224d4de5c04a371bb5404b866910
sha256: 9638d71f662a31c4cfb70991ccfbe8264ad7c0f413805c254307cf4da2a8757d
sha512: 7fb7644fe9c2967ecd2dffa871d2c60dbd092501f108959be9d4d5dafa01efaf68aa9d996c85279cde101210093af931e273e27e5ac6fc99d4cb08ce6b9534dd
ssdeep: 6144:pPKl2hEAx/P6bR7iImMtK/tm987J2TfV6UXiB4jkQ0tGNKM:pZplibtiIw/k8gTN6AF4Mb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.KTZJFBT also known as:

McAfeeArtemis!CCBCA3143707
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32965312
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroTrojan.Win32.WACATAC.THABOBO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KTZJFBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.amqnt
RisingTrojan.Hancitor!8.B197 (RDMK:cmRtazpT8GMEQcoBa8uSd7Ys1hut)
Ad-AwareTrojan.GenericKD.32965312
EmsisoftTrojan.GenericKD.32965312 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.gh
FortinetW32/Generik.KTZJFBT!tr
FireEyeGeneric.mg.ccbca3143707a91c
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
MAXmalware (ai score=80)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F702C0
ZoneAlarmTrojan.Win32.Inject.amqnt
MicrosoftTrojan:Win32/Wacatac.C!ml
ALYacTrojan.Agent.Wacatac
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.WACATAC.THABOBO
TencentWin32.Trojan.Inject.Tcci
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKD.32965312
BitDefenderThetaGen:NN.ZexaF.34084.zyZ@a83b!aic
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.4d9d92
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Generic/HEUR/QVM08.0.AEB9.Malware.Gen

How to remove Generik.KTZJFBT?

Generik.KTZJFBT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment