Malware

Generik.IPMOIFN (file analysis)

Malware Removal

The Generik.IPMOIFN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.IPMOIFN virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Generik.IPMOIFN?


File Info:

crc32: 5B8C3873
md5: 13ffe34c76cf695e245cb7ee79e476f2
name: 27010806667.exe
sha1: 55f144197a5451b908d9bbbe5c1efcb7a8fcf943
sha256: 1905469bdbfcbb6e6517bccd8a826ba6989497b0df8bae4e7abe9dc7313ffb72
sha512: 09011405270cca73376959b20cb4b0918dff93b5435e6d61734d9e00acf81fbe97cd270a133c30455c68f2d498755a71b925d695556ff1bcb31200ff5f907745
ssdeep: 49152:CNyCBYLNWRt8Sk8Vx8bzggCXDBw4IXuLlGuDHy3gJ1gA:Cfwqq2szTg2ZXupGCJN
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: Base.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WindowsFormsApp14
ProductVersion: 1.0.0.0
FileDescription: WindowsFormsApp14
OriginalFilename: Base.exe

Generik.IPMOIFN also known as:

MicroWorld-eScanGen:Variant.Razy.574255
FireEyeGen:Variant.Razy.574255
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Razy.574255
CylanceUnsafe
ZillyaTrojan.Crypt.Win32.60725
SangforMalware
BitDefenderGen:Variant.Razy.574255
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R057C0PB820
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Razy.574255
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:MSIL/Kryptik.9c151042
ViRobotTrojan.Win32.Z.Razy.2051072.B
AegisLabTrojan.MSIL.Crypt.4!c
RisingTrojan.Crypt!8.2E3 (CLOUD)
Ad-AwareGen:Variant.Razy.574255
EmsisoftGen:Variant.Razy.574255 (B)
F-SecureTrojan.TR/Kryptik.imsyc
DrWebTrojan.DownLoader27.50129
McAfee-GW-EditionGenericRXJA-HM!13FFE34C76CF
SophosMal/Generic-S
IkarusTrojan.Crypt
CyrenW32/Trojan.ZIYV-4610
JiangminTrojan.MSIL.nnxl
AviraTR/Kryptik.imsyc
Antiy-AVLTrojan/MSIL.Crypt
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8C32F
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Agent.C3298422
McAfeeGenericRXJA-HM!13FFE34C76CF
MAXmalware (ai score=89)
VBA32Trojan.MSIL.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.IPMOIFN
TrendMicro-HouseCallTROJ_GEN.R057C0PB820
TencentMsil.Trojan.Crypt.Dzul
YandexTrojan.Crypt!Aq5PXD/hxXU
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_87%
FortinetW32/Crypt.HM!tr
BitDefenderThetaGen:NN.ZemsilF.34090.9n0@aWRMvYb
AVGWin32:Malware-gen
Qihoo-360Generic/Trojan.21a

How to remove Generik.IPMOIFN?

Generik.IPMOIFN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment