Malware

Generik.CCHXRXI (file analysis)

Malware Removal

The Generik.CCHXRXI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.CCHXRXI virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generik.CCHXRXI?


File Info:

crc32: 882F95A5
md5: 96683a06a09fe0a538871a96f07369c9
name: 96683A06A09FE0A538871A96F07369C9.mlw
sha1: 7ae86dc9635a14a1f6b7acc8e6f6d2263e531367
sha256: 229e27d75b86582a1c728de0898c3a8193f463db7b07176ac6cde7bbc8e9883a
sha512: 09256e7adc524a95adad6cbe48c832947a262215b47b27e222e2c38bf80873aefadd9e49ae5a8ffc513a4f83cd98256555ea13fc9de04ec6414c9adaf5c45b9b
ssdeep: 49152:lpgjVD5stTlpelVMFnLrW9FTko5Zalry1DCVfZPJIMQH4/JoUdC:lpgjraefMFnLrW9FIoGZg2rj66oUdC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.CCHXRXI also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:MSIL/Seraph.0ea08056
K7GWTrojan ( 0057b1ef1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.CCHXRXI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.MSIL.Seraph.nh
SophosMal/Generic-S
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.96683a06a09fe0a5
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Agent.V61MS4
McAfeeArtemis!96683A06A09F
RisingSpyware.Pavica!8.6B1 (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Pavica.FM!tr.spy
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Generik.CCHXRXI?

Generik.CCHXRXI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment