Malware

Generik.HZKOQNT (file analysis)

Malware Removal

The Generik.HZKOQNT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.HZKOQNT virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generik.HZKOQNT?


File Info:

name: 9E67F2B231B215550123.mlw
path: /opt/CAPEv2/storage/binaries/74c6de6cbf1fbf85f8c9bcb20e981215bf14d61559eca8fbb231fa06c017aaf8
crc32: B196DEB0
md5: 9e67f2b231b215550123d8546bda9ed4
sha1: 1459115581e91a4ce886b8c924416ea2e2e826c1
sha256: 74c6de6cbf1fbf85f8c9bcb20e981215bf14d61559eca8fbb231fa06c017aaf8
sha512: ed4a720361c3fddbab7fdf3816108d607b0588fc90bf41bd05a7e0b7dc4b749725b86c3c14b8824025a8967584af2d3168a62ba226dd9e374dd331fb5c327d4d
ssdeep: 196608:OEGTRc+uA4txswkUPHQ1NrOF39b5Hk13t8Epyf/olcUJ7FJxATQQGIPL3Js8CRP0:ZycRCj1hOFx09of/e3pxWFPLZQRP5/G
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FCE6239F2DCB40E9D9C118A4E32B6BD713F392B54AC94C3565C13149B0F2FBA607E989
sha3_384: 43f47c2c4395d9cdc2a095e5b86c931015529de0457bc54b83c83f89655fc4cf44d6fca473d8187f50afa14e9a92a0a1
ep_bytes: e83fb475ff488bb41475ffffff66c1cf
timestamp: 2024-03-02 21:11:36

Version Info:

CompanyName: Uriel Anti-Cheat
FileDescription: Usermode anti-cheat module for metin2
FileVersion: 1.8.0.0
InternalName: client_x86.dll
LegalCopyright: Copyright (C) 2024 - Uriel Anti-Cheat
OriginalFilename: client_x86.dll
ProductName: Uriel Anti-Cheat
ProductVersion: 1.8.0.0
Translation: 0x0409 0x04b0

Generik.HZKOQNT also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 99)
SkyhighArtemis
McAfeeArtemis!9E67F2B231B2
Cylanceunsafe
AlibabaTrojan:Win32/Generic.6e5b2f73
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HZKOQNT
KasperskyTrojan.Win32.Agent.xblvkw
BitDefenderTrojan.GenericKD.71823977
MicroWorld-eScanTrojan.GenericKD.71823977
AvastWin32:Malware-gen
RisingTrojan.MalCert!1.DA97 (CLASSIC)
EmsisoftTrojan.GenericKD.71823977 (B)
F-SecureTrojan.TR/Agent.lnoha
DrWebTrojan.Packed.189
FireEyeTrojan.GenericKD.71823977
SophosMal/Generic-S
AviraTR/Agent.lnoha
KingsoftWin32.Trojan.Agent.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D447F269
ZoneAlarmTrojan.Win32.Agent.xblvkw
GDataTrojan.GenericKD.71823977
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R637636
VBA32BScope.TrojanPSW.Coins
ALYacTrojan.GenericKD.71823977
MAXmalware (ai score=84)
TencentWin32.Trojan.FalseSign.Mqil
IkarusTrojan.Win64.Vmprotect
MaxSecureTrojan.Malware.235274817.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Generik.HZKOQNT?

Generik.HZKOQNT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment