Malware

Generik.EQCNHWR (file analysis)

Malware Removal

The Generik.EQCNHWR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.EQCNHWR virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking

How to determine Generik.EQCNHWR?


File Info:

crc32: 0A65FC14
md5: 8f5424704f60bab16a8a80af64ddb3d8
name: 8F5424704F60BAB16A8A80AF64DDB3D8.mlw
sha1: 98b9adab6afb0b25ebdac263ae9ce128eb4260a3
sha256: 7b8e7a560163bdafe4d7ca8562f6a04dfc1835100ca22037e410f74056508c48
sha512: d85d6e34d854b47a8b208aec8157cacf438d0362db36ae57321a30272e008056b8b5ba6787fd31dc9a78de738ce5b3e6674c2cae9deee33dcced3cd1638cc995
ssdeep: 6144:KCgWvBNc+pnhbQvwy7ryRO8p42iSP2Re8J2m:KCgWvBNBpnFQvwy7rywPvkK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 234234 23 4
InternalName: 23 424
FileVersion: 423423 4
FileDescription: 2 34242
ProductName: 535345345
ProductVersion: 3453453453453
PrivateBuild: 535
OriginalFilename: 23 43t3t
Translation: 0x0419 0x04b0

Generik.EQCNHWR also known as:

K7AntiVirusTrojan ( 0057a2151 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46016260
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanPSW:Win32/Agensla.cd02d7e8
K7GWTrojan ( 0057a2151 )
Cybereasonmalicious.b6afb0
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.EQCNHWR
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
BitDefenderTrojan.GenericKD.46016260
MicroWorld-eScanTrojan.GenericKD.46016260
Ad-AwareTrojan.GenericKD.46016260
BitDefenderThetaGen:NN.ZexaF.34670.Mq3@aqRBx1ac
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.jm
FireEyeGeneric.mg.8f5424704f60bab1
EmsisoftTrojan.GenericKD.46016260 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Goldfin.zumae
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Generic.D2BE2704
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.46016260
AhnLab-V3Malware/Win.Reputation.R414522
McAfeeArtemis!8F5424704F60
MAXmalware (ai score=80)
VBA32BScope.Trojan.Zbot.01371
MalwarebytesMalware.AI.860842627
PandaTrj/CI.A
RisingTrojan.Kryptik!1.CBAA (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Generik.EQCNHWR!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Generik.EQCNHWR?

Generik.EQCNHWR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment