Malware

Generik.NCPFCHW removal instruction

Malware Removal

The Generik.NCPFCHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NCPFCHW virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Detects Sandboxie through the presence of a library
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
crossout1.com
www.husket.net

How to determine Generik.NCPFCHW?


File Info:

crc32: C254A798
md5: 6e9e4b4a307cec04a6942cdfe5cb3259
name: 6E9E4B4A307CEC04A6942CDFE5CB3259.mlw
sha1: 123f6eb2db3d5b77bceafa30afc8b45991cade8f
sha256: 36923eb37a95df2664feff29a70b5305421c3166c3151a01a47c80e270db8bec
sha512: d738c13f0121dc565af1fc388ac75d2d186e58c7c04c54b167cd3ba1fe25981373b8229aaccfde66fb12c13ae56f3bbb3180b1734da6632582d586175d108296
ssdeep: 24576:K76HUKPu8/7Y6qCtBZguQSHXOhaDaJN7b47Y6MXG6nhg9vY9GkVsU9+zUwh1Hii:PUCT/86qcZgvSHesDSN47YlrhgpbiYY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.NCPFCHW also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005392e81 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31135901
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.9464
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Gimemo.655f54fd
K7GWTrojan ( 005392e81 )
Cybereasonmalicious.a307ce
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NCPFCHW
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gimemo.cgyy
BitDefenderTrojan.GenericKD.31135901
NANO-AntivirusTrojan.Win32.Gimemo.fjubcv
MicroWorld-eScanTrojan.GenericKD.31135901
TencentWin32.Trojan.Gimemo.Wsks
Ad-AwareTrojan.GenericKD.31135901
SophosMal/Generic-S
ComodoMalware@#2y1gw83akfla3
BitDefenderThetaAI:Packer.5F9343D820
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
FireEyeGeneric.mg.6e9e4b4a307cec04
EmsisoftTrojan.GenericKD.31135901 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gimemo.vs
AviraHEUR/AGEN.1110181
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.27204A7
MicrosoftHackTool:Win32/AutoKMS!ml
ArcabitTrojan.Generic.D1DB189D
GDataTrojan.GenericKD.31135901
AhnLab-V3Malware/Win32.Generic.C2639845
Acronissuspicious
McAfeeArtemis!6E9E4B4A307C
MAXmalware (ai score=84)
VBA32suspected of Trojan.Downloader.gen
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:a0EvetYyMuaXYucyFE2p5Q)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gimemo.CGYY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generik.NCPFCHW?

Generik.NCPFCHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment