Malware

Genie.288 information

Malware Removal

The Genie.288 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Genie.288 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Genie.288?


File Info:

name: 08B6A370695B60D54FF9.mlw
path: /opt/CAPEv2/storage/binaries/2c90c887d567fd275c5a54e1ac58e5f01b090fe721ee28d1742dae2205293992
crc32: 16706216
md5: 08b6a370695b60d54ff93703343b88ca
sha1: 4f03aa5ed36d9a2a9647bcd3d3a119dabaa6bb90
sha256: 2c90c887d567fd275c5a54e1ac58e5f01b090fe721ee28d1742dae2205293992
sha512: 508b93a68dc877d723aa8cd98e289f61afe47ced524b4f4759a2e458ef911098f09205562332cb18e26e0a30f392929f203b5afd9b5f37161e988aef26e93e70
ssdeep: 6144:mBKHYmz6mq2pmHmFV2YjnWuwqzeRhvaXwvwitF:Z4m5bpnL2KnEqCRhvaXyF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16454222B29DF4CB0EB4D053942608D6C837E1E9CB244C71732627D6D5A70BAAA4057FF
sha3_384: f865b4fc5dc776d8e7d2021e446b0865f53fdc7aaa53cc45716b9b4f7fe6c368c80b81501625a6dddf249bc2767926a0
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2011-03-07 01:41:18

Version Info:

CompanyName:
FileDescription: 281600
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Genie.288 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.5793
MicroWorld-eScanGen:Variant.Genie.288
FireEyeGeneric.mg.08b6a370695b60d5
CAT-QuickHealTrojanDownloader.Delf.NK12
SkyhighBehavesLike.Win32.ObfuscatedPoly.dc
McAfeeGenericRXAA-AA!08B6A370695B
Cylanceunsafe
ZillyaDownloader.Delf.Win32.18241
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/GenDownloader.6602a0e9
K7GWTrojan ( f1000a011 )
K7AntiVirusTrojan ( f1000a011 )
BitDefenderThetaGen:NN.ZelphiF.36802.rW1bauWGOOkj
VirITTrojan.Win32.Cryptic.CBE
SymantecDownloader
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.QEW
APEXMalicious
TrendMicro-HouseCallTROJ_DLOADR.SMAI
AvastWin32:Evo-gen [Trj]
ClamAVWin.Packed.Delf-9786618-0
KasperskyTrojan-Downloader.Win32.Delf.aznp
BitDefenderGen:Variant.Genie.288
NANO-AntivirusTrojan.Win32.Delf.crlibp
SUPERAntiSpywareTrojan.Agent/Gen-Delf
TencentTrojan.Win32.Downloader.tgx
EmsisoftGen:Variant.Genie.288 (B)
GoogleDetected
F-SecureTrojan.TR/Dldr.Delphi.Gen
BaiduWin32.Trojan-Downloader.Agent.af
VIPREGen:Variant.Genie.288
TrendMicroTROJ_DLOADR.SMAI
Trapminemalicious.high.ml.score
SophosMal/DelpDwnld-B
JiangminTrojanDownloader.Delf.aafj
VaristW32/Delf.AI.gen!Eldorado
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/Win32.Delf
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Delf
XcitiumTrojWare.Win32.Downloader.Fraudload.AA@2vwxs7
ArcabitTrojan.Genie.288
ViRobotTrojan.Win32.A.Downloader.282141[ASPack]
ZoneAlarmTrojan-Downloader.Win32.Delf.aznp
GDataGen:Variant.Genie.288
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Delf.R3483
VBA32TrojanDownloader.Delf
ALYacGen:Variant.Genie.288
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.DL.Win32.Undef.tit (CLOUD)
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Delf.AZNP
FortinetW32/Delf.QEW!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudRiskWare:Win/ASPacked

How to remove Genie.288?

Genie.288 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment