Malware

Generik.MCKGZWP removal tips

Malware Removal

The Generik.MCKGZWP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.MCKGZWP virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
ocsp.usertrust.com
crl.usertrust.com
ocsp.comodoca.com
crl.comodoca.com

How to determine Generik.MCKGZWP?


File Info:

crc32: BDBBE0A4
md5: 1f4685b4f9f317f773aac4d1acbf8337
name: upload_file
sha1: e9e1498cbb1a291b7e5cfb0ce349a8f23333fde4
sha256: d2806cacd63cf6c3d3eb2d46dd5ad415a5a6f4f35d325d72145228a19b53403b
sha512: 1318b6f9991f03bb97354cc6fffed679da7bde2076cb20230c46e3837f35c3790d2c1724ab07219981d29a3ec8bdcb212d087224a85ac0cedeb9f98dc87501de
ssdeep: 6144:jisFUJa3LzXV92XEY+RUvyygiY5pN9+ec3a8YAERDNdijiK8zO2GlO7vowUxC:mzabzls3vyhB5P9BJAeDNdij1tMvork
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.2
InternalName: BPZub2SWAttr.exe
FileVersion: 1.0.0.2
CompanyName: Compusoft Hard- & Software GmbH
LegalTrademarks: Compusoft GmbH
Comments: xdcbertrxe4gt die Zubehxf6rdaten in den Shop RPX 1.3.4702.1473
ProductName: BPZub2SWAttr
ProductVersion: 1.0.0.2
FileDescription: BPZub2SWAttr
OriginalFilename: BPZub2SWAttr.exe

Generik.MCKGZWP also known as:

Elasticmalicious (high confidence)
McAfeeArtemis!1F4685B4F9F3
CylanceUnsafe
ZillyaTrojan.CryptCRTD.Win32.12054
SangforMalware
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.MSIL.Crypt.erao
AlibabaTrojan:MSIL/Generic.b877c695
NANO-AntivirusTrojan.Win32.Crypt.esrdhq
RisingTrojan.Crypt!8.2E3 (CLOUD)
ComodoMalware@#zh87m58wp5us
VIPRETrojan.Win32.Generic!BT
FortinetMSIL/Generic.AP.189EF30!tr
FireEyeGeneric.mg.1f4685b4f9f317f7
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.MSIL.gzag
MAXmalware (ai score=97)
Antiy-AVLTrojan/Win32.TSGeneric
ZoneAlarmTrojan.MSIL.Crypt.erao
MicrosoftTrojan:Win32/Ymacco.AAD2
AhnLab-V3Trojan/Win32.Agent.C4129745
PandaTrj/CI.A
ESET-NOD32a variant of Generik.MCKGZWP
TrendMicro-HouseCallTROJ_GEN.R002H0CHJ20
TencentMsil.Trojan.Crypt.Eady
IkarusTrojan.MSIL.Crypt
AVGFileRepMalware
Cybereasonmalicious.cbb1a2
Qihoo-360Generic/Trojan.513

How to remove Generik.MCKGZWP?

Generik.MCKGZWP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment