Malware

Generik.GQOOEEA (file analysis)

Malware Removal

The Generik.GQOOEEA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.GQOOEEA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • CAPE detected the CryptBot malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.GQOOEEA?


File Info:

name: E36B523D93473449F5C8.mlw
path: /opt/CAPEv2/storage/binaries/437a6361d8c66fb3f5df03056224d037de601314988566ab98b0dd421b5ce516
crc32: 0F46BC14
md5: e36b523d93473449f5c8b275e70f19d8
sha1: 995176177171d943ede814a82a84b546f096e4ad
sha256: 437a6361d8c66fb3f5df03056224d037de601314988566ab98b0dd421b5ce516
sha512: 1ad647548f1323ecfc9ebb5ad03cd79fb99b9cbde68c0ee6ccafb3d62ca475c0f5936fe9abb5eec8c1d3ba9b5781057e078cbe25da25f058d56d41493f49d284
ssdeep: 49152:HOFHgfEo5YB7jU8/c9b/LI6cx6GXp0www5aDzK9iCcOFP0xg:HcHMEo5YB7jU8/c9DL3e6E5haQcy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8F58C91F600D5A2D8298630D93789F8A1657CAAECD0152F71CC7F5FBE72383225AD1E
sha3_384: 5e49014c944f797cc38bd9a28b7532764faa2b8d1d8a1eefc1adab8f764bc093cc625ae2d0ca92aae1fb8fa899c2563d
ep_bytes: 31d2526877964000c333c833c833c88b
timestamp: 2021-12-07 05:01:01

Version Info:

FileVersion: 6, 0, 7, 7
Comments: Bountith
CompanyName: Promt
InternalName: Posterize
Unprescinded: Ellipticity
Sabered: Quicksilvering
Abidi: Mistrustfully
Dissatisfactory: Wurmian
Bepuff: Vastitude
Inport: Murine
Semasiology: Crowder
Dentification: Concertinist
Reaggressive: Synclinorian
Nonriparian: Wringman
Agrologically: Macrosomatia
Temperately: Paleopicrite
Effectualize: Nurserydom
Junketer: Serena
Combinant: Conjugational
Motorphobiac: Unrueful
Outset: Switzeress
Biblic: Contumaciousness
Isogamic: Zibetum
Topiarius: Octovalent
Spotlessness: Nonconficient
Kella: Puddled
Anorthose: Rudderless
Ultralegality: Delator
Avick: Pharos
Untorture: Fontinalaceae
Synclinorian: Undisinheritable
Marcasite: Rudderless
Warehou: Antiepileptic
Equerryship: Hoodshyness
Albicant: Uncoaxed
Beeve: Monheimite
Quadrumanal: Entertaining
Anthroponomist: Railwayless
Acmesthesia: Ornithorhynchous
Photoisomerization: Isographical
Unstrengthen: Skilts
Possessingly: Tiresomeness
Mesobregmate: Afreet
Rhomborectangular: Recruitee
Microrheometric: Scarificator
Aecidioform: Fatherhood
Unexemplifiable: Lyomerous
Phototopography: Paillette
Implausibly: Hoplitodromos
Unsnare: Benzthiophen
Untitled: Trionychidae
Reinterference: Lubricational
Thornless: Microgeology
Unpummeled: Broodlet
Vertebrocostal: Limpsy
Titled: Thirstiness
Coracoclavicular: Amazingly
Preobject: Osteitis
Aeolsklavier: Phyllophore
Voting: Lyard
Firedamp: Aposematically
Lysenkoism: Almsdeed
Sangirese: Uniat
Mobocratic: Platybrachycephalic
OriginalFilename: Phosphorism
PrivateBuild: Phaneroglossa
Translation: 0x0409 0x04e4

Generik.GQOOEEA also known as:

MicroWorld-eScanTrojan.GenericKD.47589048
FireEyeGeneric.mg.e36b523d93473449
McAfeeArtemis!E36B523D9347
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/SelfDel.7e6ae8b0
K7GWTrojan ( 0058b96a1 )
K7AntiVirusTrojan ( 0058b96a1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.GQOOEEA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SelfDel.hvvf
BitDefenderTrojan.GenericKD.47589048
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.47589048
EmsisoftTrojan.GenericKD.47589048 (B)
Comodofls.noname@0
DrWebTrojan.Siggen16.257
TrendMicroTrojan.Win32.COINSTEALER.USMANL821
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.CoinStealer
GDataTrojan.GenericKD.47589048
WebrootW32.Malware.Gen
AviraTR/AD.GenSteal.mljfh
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R457157
ALYacTrojan.GenericKD.47589048
MAXmalware (ai score=89)
VBA32Trojan.SelfDel
TrendMicro-HouseCallTrojan.Win32.COINSTEALER.USMANL821
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/PossibleThreat
AVGFileRepMalware
PandaTrj/GdSda.A

How to remove Generik.GQOOEEA?

Generik.GQOOEEA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment