Trojan

How to remove “Trojan.Generic.KDZ.2075”?

Malware Removal

The Trojan.Generic.KDZ.2075 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.KDZ.2075 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • NtSetInformationThread: attempt to hide thread from debugger
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Generic.KDZ.2075?


File Info:

name: FBF7E4C4537CB3979C87.mlw
path: /opt/CAPEv2/storage/binaries/4a44585d679a40b9f69621610c0250af045d75f0f42ed2d7c4cc5d4ea82b6628
crc32: 46ADC870
md5: fbf7e4c4537cb3979c87972a851ee4d3
sha1: 3124690749b240120ac11d8b1e1857194df9c2b4
sha256: 4a44585d679a40b9f69621610c0250af045d75f0f42ed2d7c4cc5d4ea82b6628
sha512: 72c44384dda4bd4d902584550e2b67cd63bb9c118b721722ed140d053c8d3910862ea493599d53be4f6fe3ccf9c758b6bb5d09fb61a410b38782081f029915e9
ssdeep: 1536:KzbzEaehTMBLIeBa3n5ReL8biW8AL+7GQkp1g:KzPohYBLIz5eWbL4I1g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB63B221758B77B8F499C1F0EE46A6911610FA1FFD0A800F71CC69BAA5BD72334AE704
sha3_384: 884e3d165fe153c2f07acbfb78b2268a960baed6a05314638cf6ee20a15dcfa3514bef835d2c2a823f41c58ddf09101b
ep_bytes: 5589e583ec08c7042402000000ff151c
timestamp: 2012-12-16 02:00:47

Version Info:

CompanyName:
FileVersion:
FileDescription:
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x041c 0x04e4

Trojan.Generic.KDZ.2075 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fbf7e4c4537cb397
CAT-QuickHealVirtool.CeeInject.EG
McAfeePWS-Zbot.gen.asv
CylanceUnsafe
VIPREVirTool.Win32.CeeInject.gen.hlc (v)
SangforTrojan.Win32.XPACK.Gen
K7AntiVirusTrojan ( 0040f03f1 )
AlibabaVirTool:Win32/CeeInject.8d553633
K7GWTrojan ( 0040f03f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.IF.gen!Eldorado
SymantecPacked.Generic.397
ESET-NOD32a variant of Win32/Injector.AAGM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.KDZ.2075
NANO-AntivirusTrojan.Win32.Crypted.belezh
MicroWorld-eScanTrojan.Generic.KDZ.2075
AvastWin32:Crypt-OPN [Trj]
TencentWin32.Trojan.Generic.Eibn
Ad-AwareTrojan.Generic.KDZ.2075
EmsisoftTrojan.Generic.KDZ.2075 (B)
ComodoTrojWare.Win32.PWS.ZBot.ATB@4sozjf
DrWebTrojan.DownLoader7.15160
ZillyaTrojan.Injector.Win32.407380
TrendMicroTROJ_CINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.ZBot.kc
SophosMal/Generic-R + Troj/Ransom-LN
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.KDZ.2075
JiangminTrojan/Generic.arnfx
eGambitGeneric.Downloader
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.212E57
KingsoftWin32.Troj.Yakes.bo.(kcloud)
MicrosoftVirTool:Win32/CeeInject.gen!HL
AhnLab-V3Spyware/Win32.Zbot.R46834
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.eG0@auzWXZdi
ALYacTrojan.Generic.KDZ.2075
VBA32Trojan.EA.01671
MalwarebytesTrojan.Winlock
TrendMicro-HouseCallTROJ_CINJECT.SMA
RisingTrojan.Mingc!1.660C (CLOUD)
YandexTrojan.GenAsa!/1lw+YralD0
IkarusVirus.Win32.CeeInject
MaxSecureTrojan.Malware.5057862.susgen
FortinetW32/Zbot.AAU!tr
WebrootW32.Rogue.Gen
AVGWin32:Crypt-OPN [Trj]
Cybereasonmalicious.4537cb
PandaTrj/Genetic.gen

How to remove Trojan.Generic.KDZ.2075?

Trojan.Generic.KDZ.2075 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment