Malware

Generik.DDNECDF removal guide

Malware Removal

The Generik.DDNECDF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.DDNECDF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • A process sent information about the computer to a remote location.
  • Anomalous binary characteristics

Related domains:

api.ipify.org
speritentz.com
wouatiareves.ru

How to determine Generik.DDNECDF?


File Info:

crc32: 78FFD354
md5: 4bcf25af987fa12ed441529c4b0293b7
name: 4BCF25AF987FA12ED441529C4B0293B7.mlw
sha1: 6832afc831acf8cb7ab0df76ae140093a4ae961b
sha256: 5d70694b5395e40edfa8c08b7727d3ceea9de8b17b789727a9234cd4f7f44ed1
sha512: c0da04d503f98923323400996bcf0147f6f67e3fd8bf245cfda3749cf43e31b9c74b83dbada17b84523eb6f215072a67941edb87e7803f877afa6d6f5c66ba06
ssdeep: 6144:V17lp2D7gWtgvbBBSjaQuWZJSYBMS4kPf4myr2JlzjhOsjdAO2fbma5/LOH:V17lp2D7gWtUSvuWZJB34myr2H/BRGb
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Horse base 1995-2019
Begin: 235
FileVersion: 6.5.3.821
CompanyName: Horse base
ProductName: Sent
ProductVersion: 6.5
FileDescription: Sent spread
OriginalFilename: opposite.dll
Translation: 0x0409 0x04e4

Generik.DDNECDF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36401101
FireEyeTrojan.GenericKD.36401101
CAT-QuickHealTrojan.Multi
McAfeeGenericRXAA-AA!4BCF25AF987F
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Hancitor.ARK
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.36401101
K7GWTrojan ( 0057866d1 )
K7AntiVirusTrojan ( 0057866d1 )
CyrenW32/Trojan.NESC-5808
SymantecTrojan Horse
ESET-NOD32a variant of Generik.DDNECDF
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyTrojan-Banker.Win32.Cridex.ahjw
ViRobotTrojan.Win32.Z.Agent.359424.JB
RisingTrojan.Hancitor!8.B197 (CLOUD)
Ad-AwareTrojan.GenericKD.36401101
EmsisoftTrojan.GenericKD.36401101 (B)
ComodoTrojWare.Win32.UMal.zgxvn@0
F-SecureTrojan.TR/AD.ZDlder.ledfg
DrWebTrojan.Chanitor.59
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/AD.ZDlder.ledfg
MAXmalware (ai score=87)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Hancitor.ARK!MTB
ArcabitTrojan.Generic.D22B6FCD
AhnLab-V3Malware/Win32.RL_Generic.R368335
ZoneAlarmTrojan-Banker.Win32.Cridex.ahjw
GDataTrojan.GenericKD.36401101
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36401101
PandaTrj/CI.A
FortinetW32/GenKryptik.FCFC!tr
WebrootW32.Trojan.Gen
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dridex.HgkASPwA

How to remove Generik.DDNECDF?

Generik.DDNECDF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment