Malware

Generik.LRTPABT removal guide

Malware Removal

The Generik.LRTPABT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.LRTPABT virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detected Armadillo packer using a known mutex
  • Detected Armadillo packer using a known registry key
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.LRTPABT?


File Info:

crc32: 443C32D0
md5: fe58ab0c63d815dbfd496cacf4a0fe5d
name: Power-Data-Recovery-7.0.exe
sha1: c7fdba5b13fe2f37ae45150a387107c4deaebda8
sha256: b3601787b0b0becb17eb053d5fa1a7b31254eac3766c4ea1c15e9c8d23103d88
sha512: 7bbc83169a2cb8b5a3019a21071b94b5dd53863cac63b3b94f99b6b30a000d4f935f346ab542cb2b5a8fd2257d440f48f1cc2a537b70f883a6577ecffa557fc2
ssdeep: 98304:MhmFEaNmOHDqI4Ue1CNNRrZDK6KxkvtmkJuwLmBBRuqEYcRQ:MhmVmQHw1CDRrBmmu2ereQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006-2010 Thomas Schulz
FileVersion:
CompanyName: Microsys
Comments: This installation was built with Inno Setup.
ProductName: A1 Website Download
ProductVersion:
FileDescription: A1 Website Download Setup
Translation: 0x0000 0x04b0

Generik.LRTPABT also known as:

McAfeeArtemis!FE58AB0C63D8
CylanceUnsafe
ZillyaTrojan.Generic.Win32.80909
SangforMalware
K7AntiVirusRiskware ( 0049c6851 )
AlibabaTrojan:Win32/Generic.8c09a4af
K7GWRiskware ( 0049c6851 )
SymantecTrojan.ADH.2
TrendMicro-HouseCallTROJ_GEN.R066H0CI619
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Jorik.bmdycg
Paloaltogeneric.ml
RisingTrojan.Generic!8.C3 (CLOUD)
ComodoMalware@#5g8bxjpklwt7
F-SecureTrojan.TR/Dldr.jew.17
DrWebTrojan.Siggen6.34654
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
JiangminTrojan/Generic.bhfcd
WebrootW32.Gen.BT
AviraTR/Dldr.jew.17
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftPUA:Win32/CoinMiner
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmTrojan.Win32.Generic
GDataWin32.Trojan.Agent.6LRR8Q
VBA32Trojan.Generic
ESET-NOD32a variant of Generik.LRTPABT
TencentWin32.Trojan.Dropper.dsii
YandexTrojan.Agent!7LNra9ispms
IkarusTrojan-Downloader.jew
eGambitGeneric.Malware
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.74b

How to remove Generik.LRTPABT?

Generik.LRTPABT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment