Malware

What is “Generic.Rincux2.2889BD38”?

Malware Removal

The Generic.Rincux2.2889BD38 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rincux2.2889BD38 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • CAPE detected the Nitol malware family

How to determine Generic.Rincux2.2889BD38?


File Info:

name: 9CBF65059A2C0A95C778.mlw
path: /opt/CAPEv2/storage/binaries/580156ff431d03739c4252df89cdf2c6f306bce333190718ef37292050860491
crc32: E828BE71
md5: 9cbf65059a2c0a95c77854e6d8c2b0ed
sha1: 70c161635f52671bd8e8630630d7a6684bcf6d49
sha256: 580156ff431d03739c4252df89cdf2c6f306bce333190718ef37292050860491
sha512: 9baf7eb05962c77e7cd1e2dfd5827acd130fea3ad0fe51a3a9d74bbd5b8ac22bbca5a7557bcf8b86009d0fb7a6f2f1a59579bfe98bdd9d19f7315e0a03fbcc73
ssdeep: 1536:52eUi3tuk7hyRelXmBK9aB4PL4Ee2eUsQOa:/hdllyio2aB4sTUhOa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10863E116FB0DDF9CD8414036D7638FB54599B01B81074B13AA2BAB8FED78760AC0BDA5
sha3_384: 1d57dd9f460bb85d65f12647d84013ac6e04b0c2a2da2e8d86b800ec75d36f913f05533c024db896a28f14d5e7eed00b
ep_bytes: 60be00f044008dbe0020fbff5783cdff
timestamp: 2020-09-01 11:30:04

Version Info:

CompanyName:
FileDescription: Style Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: Style
LegalCopyright: 版权所有 (C) 2005
LegalTrademarks:
OriginalFilename: Style.EXE
ProductName: Style 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Generic.Rincux2.2889BD38 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanDeepScan:Generic.Rincux2.2889BD38
FireEyeGeneric.mg.9cbf65059a2c0a95
McAfeeGenericRXMC-FT!429FF08B4312
CylanceUnsafe
VIPREDeepScan:Generic.Rincux2.2889BD38
K7AntiVirusTrojan ( 0056f5b81 )
BitDefenderDeepScan:Generic.Rincux2.2889BD38
K7GWTrojan ( 0056f5b81 )
Cybereasonmalicious.59a2c0
ArcabitDeepScan:Generic.Rincux2.2889BD38
BitDefenderThetaGen:NN.ZexaF.34806.emKfa0xho2cb
CyrenW32/Farfli.DWDE-7153
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.CXE
APEXMalicious
ClamAVWin.Trojan.Farfli-9790741-0
KasperskyHEUR:Backdoor.Win32.Farfli.gen
NANO-AntivirusTrojan.Win32.Farfli.hymocx
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareDeepScan:Generic.Rincux2.2889BD38
SophosMal/Generic-S
ComodoTrojWare.Win32.Magania.A@5wdy5u
DrWebTrojan.DownLoader34.44014
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionGenericRXMC-FT!429FF08B4312
Trapminemalicious.high.ml.score
EmsisoftDeepScan:Generic.Rincux2.2889BD38 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.eak
AviraHEUR/AGEN.1205729
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.26E9
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDeepScan:Generic.Rincux2.2889BD38
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Backdoor.R353637
Acronissuspicious
VBA32BScope.Trojan.Fsysna
ALYacDeepScan:Generic.Rincux2.2889BD38
TACHYONBackdoor/W32.Farfli.368640.E
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
TencentBackdoor.Win32.farfli.16000311
YandexTrojan.Farfli!FxbzUVVciGA
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.EOZH!tr
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generic.Rincux2.2889BD38?

Generic.Rincux2.2889BD38 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment