Malware

About “GenScript.KLB” infection

Malware Removal

The GenScript.KLB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenScript.KLB virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine GenScript.KLB?


File Info:

crc32: 45AE0F0B
md5: 520c6c2d15d6439bf5bcf95b708accd7
name: upload_file
sha1: 97da807f1b529e9bb78835713e8aeabe813cd98d
sha256: f41e1405b2d7c19b814170232d477a3bacfedada428b26a6aa4f2ef1830f5bef
sha512: d89598d4aa89626ac2abb5106b2b055cdb0c1a0a4145a1b50ab7e0913de5af4b90ada923b4a6fea79b3eb6a7b0863e1e030a05a95387fe27a6c78304b05836f5
ssdeep: 6144:ck3hOdsylKlgryzc4bNhZF+E+W2knXPJVbTc0i+VLvuD+ktU5ljqv2tyl0dJdpa:v1Q+mOxbtyaPdpC0ccnXw
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Dell, Last Saved By: Dell, Create Time/Date: Wed Oct 14 10:36:37 2020, Last Saved Time/Date: Wed Oct 14 10:36:37 2020, Security: 0

Version Info:

0: [No Data]

GenScript.KLB also known as:

Elasticmalicious (high confidence)
DrWebExploit.Siggen2.48681
MicroWorld-eScanTrojan.GenericKD.44070939
CAT-QuickHealXMLS.VBAPurging.38956
AegisLabTrojan.Script.Generic.a!c
ArcabitHEUR.VBA.CG.1
CyrenX97M/Agent.HR
SymantecW97M.Downloader
TrendMicro-HouseCallTROJ_FRS.VSNTJE20
KasperskyHEUR:Trojan-Downloader.Script.Generic
BitDefenderTrojan.GenericKD.44070939
Ad-AwareTrojan.GenericKD.44070939
TrendMicroTROJ_FRS.VSNTJE20
McAfee-GW-EditionBehavesLike.OLE2.Downloader.fb
FireEyeTrojan.GenericKD.44070939
EmsisoftTrojan.GenericKD.44070939 (B)
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataTrojan.GenericKD.44070939
ALYacTrojan.GenericKD.44070939
TACHYONTrojan/XF.PS.Gen
ZonerProbably Heur.W97ShellB
ESET-NOD32GenScript.KLB
IkarusWin32.SuspectCrc
FortinetVBA/Agent.BLX!tr.dldr
Qihoo-360Generic/Trojan.Downloader.251

How to remove GenScript.KLB?

GenScript.KLB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment