Malware

Generik.HECNCMC removal tips

Malware Removal

The Generik.HECNCMC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HECNCMC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: FA2B4B8549B50219A008.mlw
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.HECNCMC?


File Info:

name: FA2B4B8549B50219A008.mlw
path: /opt/CAPEv2/storage/binaries/bd205a79445a67b3cd132c02ddd804cadcefd08417438f943bf07fb6e19f3d60
crc32: B491D3FB
md5: fa2b4b8549b50219a0088978cc2ed0fc
sha1: cd30ed883c8b0147bfd9c0243052ac32c1230560
sha256: bd205a79445a67b3cd132c02ddd804cadcefd08417438f943bf07fb6e19f3d60
sha512: f62ebda68a9064fb6bb910e119f221d13013b044d47a95e1dec3b160ff2a64fc77596169eb7b598bb2ebd14cb02061fd8113ebb8ed94a1a5c60b0c2c168723d4
ssdeep: 49152:1QGZAtBqE3Wn4IB5+SCqGeUbpXaez7V4U2UhbgauL8jvSqalOHQ+BqIlVRzypyv:1QGuf/DM+SCqGeheFbOYjqlUlzBy0v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151E512D4986050EED9B637B5D07A8CB509713CBAE6C53869374C316F7B3C0CB581AA2E
sha3_384: 765647f7945ba7e45586bdcd2b430a98859335b44af96a5db959f03d3c67ed8e4bf25cdc9039e02cfb8695d505459855
ep_bytes: eb059ae8b9a16450eb05d8158efed7e8
timestamp: 2021-11-07 12:29:14

Version Info:

Translation: 0x0409 0x04e4
FileVersion: 27.1.29.22
ProductName: Quicken for Windows
ProductVersion: 27.1.29.22
CompanyName: Quicken Inc.
LegalCopyright: Copyright © 2018 by Quicken Inc.
Build Date: Tue Oct 13 14:23:15 IST 2020
Build Version: 27.1.29.22
Type: QA
FileDescription: Quicken Windows
InternalName: qw.exe
OriginalFilename: qw.exe

Generik.HECNCMC also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.fa2b4b8549b50219
MalwarebytesTrojan.MalPack
BitDefenderThetaGen:NN.ZexaF.34062.!s3@aKVIljdk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HECNCMC
APEXMalicious
KasperskyVHO:Trojan-PSW.Win32.Convagent.gen
BitDefenderTrojan.GenericKDZ.81353
MicroWorld-eScanTrojan.GenericKDZ.81353
AvastFileRepMalware
Ad-AwareTrojan.GenericKDZ.81353
EmsisoftTrojan.GenericKDZ.81353 (B)
SophosGeneric ML PUA (PUA)
GDataTrojan.GenericKDZ.81353
ArcabitTrojan.Generic.D13DC9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Frs.C4797324
VBA32BScope.Trojan.Packed
ALYacGen:Variant.Jaik.49740
MAXmalware (ai score=84)
CylanceUnsafe
RisingTrojan.Generic@ML.91 (RDML:ZOI8boDZ9FcpK8uCME6p5w)
SentinelOneStatic AI – Suspicious PE
AVGFileRepMalware

How to remove Generik.HECNCMC?

Generik.HECNCMC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment