Malware

Generik.FIMBQRW (file analysis)

Malware Removal

The Generik.FIMBQRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.FIMBQRW virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
steallog.tk
a.tomx.xyz

How to determine Generik.FIMBQRW?


File Info:

crc32: 5241B3F9
md5: 7b14a66b08d68be48ee440e519a6e823
name: fxhack_v171_d29f2.exe.exe
sha1: 74a5709d1704574b8a8aff95e5ca1a7fe55b9259
sha256: 39ce4d326c146f915db4dc1193c1769b551473e3f5c7a211cc287bb0c50e0614
sha512: c4b2bfb426adf7ec56043300d5fe87ca3b6f2203f9bcc9dc4346e0b44a87bf9a1b702e5d851dcb22ede5b36b990f8bfad97b7410500800ffc93bc7f4758dd54f
ssdeep: 6144:j7eSurSFDeX68NNVcgp88UQaC0rltadNHaOLr/5jFSky3zdQwhQROpyC:P7uSxevcgpNUpQaOn5jFSkEzKRmyC
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Generik.FIMBQRW also known as:

CAT-QuickHealTrojan.Riskware
McAfeeRDN/Generic PWS.y
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.FIMBQRW
AvastWin32:Malware-gen
GDataWin32.Trojan.Agent.RPEY08
KasperskyTrojan-Spy.Win32.Stealer.pbr
AlibabaTrojanSpy:Win32/Stealer.709f9015
ViRobotTrojan.Win32.Z.Wacatac.413161
AegisLabTrojan.Win32.Stealer.l!c
RisingTrojan.HiddenRun/NSIS!1.BDAF (CLASSIC)
SophosMal/Generic-S
ComodoMalware@#ajiousjyiz9h
F-SecureHeuristic.HEUR/AGEN.1044054
DrWebTrojan.PWS.Siggen2.35786
TrendMicroTROJ_GEN.R02DC0PJQ19
McAfee-GW-EditionRDN/Generic PWS.y
AviraHEUR/AGEN.1044054
MicrosoftTrojan:Win32/Generic!BV
AhnLab-V3Trojan/Win32.Autoit.C2267953
ZoneAlarmTrojan-Spy.Win32.Stealer.pbr
Acronissuspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R02DC0PJQ19
FortinetW32/Stealer.PBR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Spy.2c8

How to remove Generik.FIMBQRW?

Generik.FIMBQRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment