Malware

Generik.ECIPFJK (file analysis)

Malware Removal

The Generik.ECIPFJK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ECIPFJK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Generik.ECIPFJK?


File Info:

name: 26A8600360599AB843BA.mlw
path: /opt/CAPEv2/storage/binaries/928bc5296bccd8d4dd8a80c0a386f5a579f9774ac33703f8ef99ea977502818e
crc32: 7BD45714
md5: 26a8600360599ab843ba124b4c5ced92
sha1: ae24d3aca64914fa50bac539082f63eaf74a7bc1
sha256: 928bc5296bccd8d4dd8a80c0a386f5a579f9774ac33703f8ef99ea977502818e
sha512: 92f4241d0a4da6ca1f36ff155a8558a77e58212309661d063fa2844562ca27780bbdfe40b02fb306e401fa31f4033399f83a77c6c52e6a65053b3be10ad71e92
ssdeep: 1536:mQ4dsAKb5NtkhrIsDiyR+cNHGHom5i1BtFb5IDK7HCZVt:4sAo5NtkhZiyR+cNHGH+1b1+jt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC939223A960A52FE096C6F1583991593827BE3207F06E4F318A6E652773643BDF071F
sha3_384: b153ea0bc108da86385171c8afc4330a9426a85ac7e778451f28606e941f54accee9abbc47904410bc574ee313282d95
ep_bytes: 6878354000e8f0ffffff000048000000
timestamp: 2007-01-31 15:20:06

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 网络X射线
ProductName: explorer
FileVersion: 1.00
ProductVersion: 1.00
InternalName: RECYCLER.BAk
OriginalFilename: RECYCLER.BAk.exe

Generik.ECIPFJK also known as:

BkavW32.Common.48A655D3
LionicTrojan.Win32.Generic.lzm8
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fm0@XCDFr9pb
FireEyeGeneric.mg.26a8600360599ab8
SkyhighBehavesLike.Win32.Generic.mm
McAfeeW32/Autorun.worm.i.gen
Cylanceunsafe
SangforWorm.Win32.AutoRun.V46t
K7AntiVirusEmailWorm ( 004a86dd1 )
AlibabaWorm:Win32/AutoRun.df270a16
K7GWEmailWorm ( 004a86dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Heur.EFA4BC
BitDefenderThetaAI:Packer.D712259A1C
VirITWorm.Win32.Generic.BVH
SymantecW32.SillyFDC
ESET-NOD32a variant of Generik.ECIPFJK
ClamAVWin.Worm.VB-2609
KasperskyWorm.Win32.AutoRun.pn
BitDefenderGen:Trojan.Heur.fm0@XCDFr9pb
NANO-AntivirusTrojan.Win32.AutoRun.toraa
AvastWin32:AutoRun-C
TencentWin32.Worm.Autorun.Ckjl
EmsisoftGen:Trojan.Heur.fm0@XCDFr9pb (B)
F-SecureTrojan.TR/VB.Recycler.A
DrWebWin32.HLLW.Autoruner.226
VIPREGen:Trojan.Heur.fm0@XCDFr9pb
TrendMicroWORM_AUTORUN.KD
SophosMal/Emogen-F
SentinelOneStatic AI – Suspicious PE
JiangminWorm.AutoRun.bmz
WebrootW32.Autorun.Gen
GoogleDetected
AviraTR/VB.Recycler.A
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.HeurC.KVM006.a
XcitiumMalware@#1mlhfjxs73uli
MicrosoftWorm:Win32/Autorun
ZoneAlarmWorm.Win32.AutoRun.pn
GDataGen:Trojan.Heur.fm0@XCDFr9pb
CynetMalicious (score: 100)
VBA32Trojan.Win32.AutoRun.be
ALYacGen:Trojan.Heur.fm0@XCDFr9pb
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
TrendMicro-HouseCallWORM_AUTORUN.KD
RisingWorm.VB.ank (CLASSIC)
YandexTrojan.GenAsa!eGAkiDL3/ok
IkarusTrojan.Mepaow
MaxSecureTrojan.Malware.862965.susgen
FortinetW32/AutoRun.BE
AVGWin32:AutoRun-C
Cybereasonmalicious.ca6491
DeepInstinctMALICIOUS

How to remove Generik.ECIPFJK?

Generik.ECIPFJK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment