Malware

Generik.ILQJGPE removal

Malware Removal

The Generik.ILQJGPE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.ILQJGPE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • A document or script wrote an executable file to disk
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • CAPE detected the RDPWrap malware family
  • Anomalous binary characteristics
  • Suspicious use of certutil was detected
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.ILQJGPE?


File Info:

name: 61C54006C5C0CA3979C4.mlw
path: /opt/CAPEv2/storage/binaries/b6cf71093407d3548e25adc93ccc867602d5d5860753d480308a81273a483bee
crc32: E2E95CC3
md5: 61c54006c5c0ca3979c46b10036072d2
sha1: 6b2e4c91c4f7eb4e8d59b3979357a5d6f7bb3dc4
sha256: b6cf71093407d3548e25adc93ccc867602d5d5860753d480308a81273a483bee
sha512: 8d3d79d917fd143db99e139dadbd080fdeac6ab6f6865334e16fd96a7803209ef99941994b13399f519cc0a7852aa64b7277eee94db74bef9d96d0791a95f146
ssdeep: 98304:P1E9Teua2zHB52xfGkKYLBJxbhIE6Sssk:P1E9TBzhQBGHylhIv8k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E0623B337427A66C918F070FB019B5D9AE9971213E046C2A5643E09DF7FC89E3F9285
sha3_384: 936d9f124b1cb6dc90aebef98b4dd5161be7f07b11107dceff6c0f0f2be6f75be55b70e9be8745914332f3e4ae5e9250
ep_bytes: 558bec6aff6878c84100684095410064
timestamp: 2016-04-02 22:14:00

Version Info:

CompanyName: Abelssoft
FileDescription: SSDFresh 2018
LegalCopyright: Copyright by Abelssoft
LegalTrademarks:
InternalName:
ProductName: SSDFresh
OriginalFilename:
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Comments: SSDFresh
PrivateBuild:
SpecialBuild:
Translation: 0x0419 0x04b0

Generik.ILQJGPE also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
CynetMalicious (score: 99)
ALYacSpyware.Infostealer.Azorult
CylanceUnsafe
SangforTrojan.Win32.MoksSteal.eoxw
K7AntiVirusTrojan ( 0055ddbd1 )
AlibabaTrojanPSW:Win32/Azorult.0141cc55
K7GWTrojan ( 0055ddbd1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MoksSteal.CTTT
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.ILQJGPE
Paloaltogeneric.ml
ClamAVWin.Malware.Azorult-9776568-0
KasperskyTrojan.Win32.Autoit.for
BitDefenderTrojan.AutoIT.Agent.AAF
NANO-AntivirusTrojan.Win32.Azorult.hbgfsg
MicroWorld-eScanTrojan.AutoIT.Agent.AAF
AvastWin32:Trojan-gen
Ad-AwareTrojan.AutoIT.Agent.AAF
EmsisoftTrojan.AutoIT.Agent.AAF (B)
ComodoMalware@#1pgi8ktf8z5by
TrendMicroTROJ_GEN.R002C0GL421
McAfee-GW-EditionPWS-FDGP!61C54006C5C0
FireEyeGeneric.mg.61c54006c5c0ca39
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataGen:Heur.PHS.1 (3x)
WebrootW32.Trojan.Gen
AviraTR/AD.MoksSteal.eoxw
ArcabitTrojan.AutoIT.Agent.AAF
ViRobotTrojan.Win32.Z.Azorult.3872881
MicrosoftTrojan:Win32/Occamy.CB6
TACHYONTrojan-Dropper/W32.Magnat.3872881
McAfeePWS-FDGP!61C54006C5C0
MAXmalware (ai score=88)
VBA32TrojanPSW.Azorult
MalwarebytesMalware.AI.1864469010
TrendMicro-HouseCallTROJ_GEN.R002C0GL421
TencentWin32.Trojan.Autoit.Wopx
YandexTrojan.PWS.Azorult!DvbQVrvjS1E
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74652977.susgen
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Trojan-gen
Cybereasonmalicious.6c5c0c
PandaTrj/CI.A

How to remove Generik.ILQJGPE?

Generik.ILQJGPE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment