Malware

How to remove “Generik.EQASMQC”?

Malware Removal

The Generik.EQASMQC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EQASMQC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 4EAA33016932917B18A7.mlw
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Generik.EQASMQC?


File Info:

name: 4EAA33016932917B18A7.mlw
path: /opt/CAPEv2/storage/binaries/358df1bb52105ce30242c792642db87dbc525a1bcfd5ad7fe5da247f1489028e
crc32: 11567974
md5: 4eaa33016932917b18a724b4286c47ed
sha1: 14397de6cd66b70334eaa6fb3a325440319a09fa
sha256: 358df1bb52105ce30242c792642db87dbc525a1bcfd5ad7fe5da247f1489028e
sha512: 43651b18be842c34834ebfe7575e29da78581933001ff088032e97fb15e28d863eb30798007794c307f306c751cb48077bc7057149c83bfc6cf24d5853410737
ssdeep: 49152:dQLiznQsIMreKKF1avBHrqvN1WTE9xoWraj+pA/sBCrr:d/ssIFK3vZrKr9xNWipJW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14175122F1296C4A6DCE42333F6E9429D9E7FEFADB410684369CC36548B31F4398E5818
sha3_384: 79b6e4713bf785323c9008913b937d76a1afb2fd08e0769529caf5b4f6a787d8b2ec04134caad76943deb83811014307
ep_bytes: eb058c8c6f9c8250eb05691e0868b5e8
timestamp: 2021-12-29 18:33:55

Version Info:

CompanyName: Glarysoft Ltd
FileDescription: Glary Utilities Installer
LegalCopyright: Copyright (c) 2003 - 2021 Glarysoft Ltd
ProductName: Glary Utilities 5
ProductVersion: 5.178.0.206
Translation: 0x0000 0x04e9

Generik.EQASMQC also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Siggen16.23192
MicroWorld-eScanTrojan.GenericKD.47787232
FireEyeGeneric.mg.4eaa33016932917b
ALYacTrojan.GenericKD.47787232
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanSpy:Win32/Stealer.5cbdd077
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.6cd66b
BitDefenderThetaGen:NN.ZexaF.34114.Gr3@aWNiXrpi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.EQASMQC
TrendMicro-HouseCallTROJ_GEN.R002C0WA322
Paloaltogeneric.ml
ClamAVWin.Dropper.Obsidium-9917799-0
KasperskyTrojan-Spy.Win32.Stealer.avzz
BitDefenderTrojan.GenericKD.47787232
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.86 (RDML:FdIF5X3Dv3UvGvr+bXy6Dw)
Ad-AwareTrojan.GenericKD.47787232
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WA322
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKD.47787232 (B)
IkarusTrojan.Win32.Obsidium
GDataWin32.Trojan-Stealer.PSWSteal.QYXQKP
KingsoftWin32.Heur.KVMH015.a.(kcloud)
MicrosoftTrojan:Win32/Vidar.AA!MTB
CynetMalicious (score: 100)
McAfeeArtemis!4EAA33016932
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack
APEXMalicious
MAXmalware (ai score=81)
FortinetMalicious_Behavior.SB
AVGWin32:Trojan-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Generik.EQASMQC?

Generik.EQASMQC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment