Malware

Generik.ENBPXWQ (file analysis)

Malware Removal

The Generik.ENBPXWQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ENBPXWQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

crl.verisign.com
aliyuns1.oss-cn-shenzhen.aliyuncs.com
www.baidu.com
www.ip.cn

How to determine Generik.ENBPXWQ?


File Info:

name: C1AAC3AE0E03D060AFF1.mlw
path: /opt/CAPEv2/storage/binaries/01b562371114f260a87dd0e29c00746a1237a3c320fd229dc2feec79e0c4e92b
crc32: 0EB7C0A7
md5: c1aac3ae0e03d060aff1821e354d6757
sha1: 5802559faad1b6bb9f5859d2d3eeabfc882d30df
sha256: 01b562371114f260a87dd0e29c00746a1237a3c320fd229dc2feec79e0c4e92b
sha512: acb4c0be65785e5cbbcea9163c56e3f5608a57d8648a1bc77f1b6a45705195712b9777840e46e379af7310527a38521652d0a2083e18a8cda8579d92401bd0b7
ssdeep: 3072:JTGypOb0kC8gtWxexNl+YW9WHHhH2mHoZnNNCOLQrkPXBFv7uOZrWCnJug:JTGypC2fHhHPIsOL1XtSe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B605E8927EA800E4C11EC53061DAF636EEE154CA15134E63E79DE3941CDA7C31AEEE2D
sha3_384: 137ac95a157325681e0ca2550d0e912ed4091b79621312b17a97060049b721b7911bcef4677c9a46df8136be78b2dbff
ep_bytes: 558bec6aff6800c240006810a2400064
timestamp: 2021-11-03 07:17:32

Version Info:

Comments: 趣日历
CompanyName:
FileDescription: 趣日历
FileVersion: 1, 0, 0, 1
InternalName: QDate
LegalCopyright: 版权所有 (C) 2021
LegalTrademarks:
OriginalFilename: QDate.EXE
PrivateBuild:
ProductName: 趣日历
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Generik.ENBPXWQ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Taskun.4!c
MicroWorld-eScanTrojan.GenericKD.47430161
FireEyeGeneric.mg.c1aac3ae0e03d060
CAT-QuickHealTrojan.Taskun
McAfeeRDN/Generic.dx
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Taskun.8c3b2aea
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.faad1b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.ENBPXWQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Taskun.gen
BitDefenderTrojan.GenericKD.47430161
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.47430161
SophosCompromised Nanjing Zhixiao CodeSigningCert (PUA)
ComodoTrojWare.Win32.Spy.Agent.04@1wm98v
DrWebTrojan.DownLoader44.1581
TrendMicroTROJ_GEN.R002C0WKK21
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.47430161 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47430161
JiangminTrojan.Taskun.e
AviraHEUR/AGEN.1145546
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2D3BA11
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R446022
ALYacTrojan.GenericKD.47430161
MAXmalware (ai score=83)
VBA32BScope.Trojan.Taskun
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0WKK21
RisingTrojan.MalCert!1.DA97 (CLASSIC)
IkarusTrojan.SuspectCRC
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
PandaTrj/CI.A

How to remove Generik.ENBPXWQ?

Generik.ENBPXWQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment