Malware

Generik.HQILBMK removal instruction

Malware Removal

The Generik.HQILBMK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HQILBMK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Generik.HQILBMK?


File Info:

crc32: 2E0C1352
md5: 77654cb69ad4ebb24dc0b227371e6ed7
name: 77654CB69AD4EBB24DC0B227371E6ED7.mlw
sha1: ca734c451757cd45c90b039b01a3754730d32575
sha256: 15190097787c425364ef05ec9762ee4ced474ee1ac93817884a8a2c79864a01e
sha512: f49bff8111b6d7308c18c60665fcecdcc5443e76783ff55762200c8ab5887a1282461e41ec7013ea1f4e2f865189820958892eda03276ba128102a1064fb36c0
ssdeep: 98304:hn8GifaM9xTEIKxL9HfgiF0mhfw2eZ1fBHLMagk8Tz9gqn1IrPztYbXdK3EJcYZ:NXifpiICGCHrA1fuT91IytChiHLVfMa
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Generik.HQILBMK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45476903
FireEyeGeneric.mg.77654cb69ad4ebb2
CAT-QuickHealTrojan.Multi
McAfeeArtemis!77654CB69AD4
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45476903
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.51757c
CyrenW32/Kryptik.CXK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Gocloudnet-9821314-0
KasperskyTrojan.Win32.Eb.bnv
AlibabaTrojan:Win32/Azorult.4c93511a
RisingTrojan.Kryptik!8.8 (TFE:5:blSGgaexi2K)
Ad-AwareTrojan.GenericKD.45476903
EmsisoftTrojan.GenericKD.45476903 (B)
TrendMicroTrojan.Win32.GLUPTEBA.WLEE
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1122056
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Azorult.MT!MTB
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Generic.D2B5EC27
ZoneAlarmTrojan.Win32.Eb.bnv
GDataTrojan.GenericKD.45476903
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.C4300033
Acronissuspicious
VBA32Trojan.Caynamer
ALYacTrojan.GenericKD.45476903
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Generik.HQILBMK
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.WLEE
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HIRY!tr
BitDefenderThetaGen:NN.ZexaF.34760.@pKfa4xyRQcG
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Generic/HEUR/QVM11.1.9C7B.Malware.Gen

How to remove Generik.HQILBMK?

Generik.HQILBMK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment