Malware

How to remove “Generik.HNXLQXE”?

Malware Removal

The Generik.HNXLQXE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HNXLQXE virus can do?

  • Authenticode signature is invalid
  • Likely installs a bootkit via raw harddisk modifications
  • Queries information on disks, possibly for anti-virtualization
  • Wrote 512 bytes to physical drive potentially indicative of overwriting the Master Boot Record (MBR)
  • Attempted to write directly to a physical drive

How to determine Generik.HNXLQXE?


File Info:

name: A8A9916266BD2CBBCA88.mlw
path: /opt/CAPEv2/storage/binaries/07f5eeb863d8e000fd24cffbf278fae627a0872afb03db01f700355656a883fd
crc32: A4B2BF90
md5: a8a9916266bd2cbbca8850c6c67a915c
sha1: 5aeb52141addd70e408761d9bdad00751b995eac
sha256: 07f5eeb863d8e000fd24cffbf278fae627a0872afb03db01f700355656a883fd
sha512: 21e11f9d7b93dceb740fe157d6cc006ad24cb92d51769c471cdd8e63da8e87eacb8350cf8365ba7b64370ec8cc5ca6800d010fa266044a9706e9e347fbb03fef
ssdeep: 192:gcUFGq6c+3a6mY49OD2JgH+q3QQ4B/W1bSyg+0SfEl:geaHYzyJE+q3QQ4B/WUyg7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E621AC71E464312E274DEB59D6A9980669EA23F03429015B77DFBA44B135FBC33306B
sha3_384: 4a2143c2d614fdc48f66b5fdafe58c589c9fefa588fb28632bc98ae5e3738529fdcb535b06f5641792f67f71cf99b116
ep_bytes: 558bec83e4f8b81c8c0000e8f0030000
timestamp: 2020-03-20 21:30:54

Version Info:

0: [No Data]

Generik.HNXLQXE also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.FU.auW@aKemQ2ii
MalwarebytesMalware.AI.4085276054
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generik.HNXLQXE
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Trojan.Heur.FU.auW@aKemQ2ii
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ransom.YMMG-5170
SymantecRansom.Petya
ESET-NOD32a variant of Generik.HNXLQXE
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Petya.3bb772ce
NANO-AntivirusTrojan.Win32.FU.hkiqdg
MicroWorld-eScanGen:Trojan.Heur.FU.auW@aKemQ2ii
TencentWin32.Trojan.Dropper.Loht
Ad-AwareGen:Trojan.Heur.FU.auW@aKemQ2ii
SophosMal/Generic-S
ComodoMalware@#y8ig1eqrzx5x
ZillyaTrojan.Generic.Win32.1056144
TrendMicroRansom_Petya.R007C0CE221
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.a8a9916266bd2cbb
EmsisoftGen:Trojan.Heur.FU.auW@aKemQ2ii (B)
IkarusTrojan-Ransom.PetYa
JiangminTrojan.Generic.fotqo
WebrootW32.Gen.BT
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.306973C
MicrosoftRansom:Win32/Petya.A
ArcabitTrojan.Heur.FU.ED694D
GDataGen:Trojan.Heur.FU.auW@aKemQ2ii
AhnLab-V3Trojan/Win32.Wacatac.C3478300
McAfeeRDN/Ransom
VBA32BScope.TrojanRansom.Petya
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Petya.R007C0CE221
RisingRansom.Petya!1.ABD1 (CLOUD)
YandexTrojan.Agent!dNkiEIUF5Bg
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic.HNXLQXE!tr
BitDefenderThetaAI:Packer.600408231F
AVGMBR:Ransom-C [Trj]
Cybereasonmalicious.266bd2
AvastMBR:Ransom-C [Trj]
MaxSecureTrojan.Malware.7164915.susgen

How to remove Generik.HNXLQXE?

Generik.HNXLQXE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment