Malware

Generik.NFOQWKE information

Malware Removal

The Generik.NFOQWKE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NFOQWKE virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

viewi.publicvm.com

How to determine Generik.NFOQWKE?


File Info:

crc32: 3D804A60
md5: 7257c27c7456d1c59bb24fb484937546
name: 7257C27C7456D1C59BB24FB484937546.mlw
sha1: 8c36bbc3f471e691a3b1c1889ef45a1f9c9d6fd2
sha256: 2a8152fcf01453e417aa48ce8b6e357fd677652ef5b0d9dcd78a39208d781b51
sha512: dcf21dcd398eaa3eee36839dc0ab911c4db90d70a2d3f5af5049bcd18be7054cfead2f8a21dfeca4720347fc6275969e19c849e75851f263325b14d8bbe659d8
ssdeep: 3072:7SEKZo1rj0IweO5DBjlMdyLKD/EKiEyV2CYefuWG1ouYe5TV:7SEKZo1rjLwV5DBjlMAm/VXzW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xe2bxe1dxe1dxe22xe31xe1dxe1axe49xe33xe48xe37xe46xe31xe21xe35xe31xe2dxe1axe2axe2axe03xe34xe1cxe49xe35xe1bxe37xe48xe37xe1b
Assembly Version: 27.29.72.54
InternalName: Assembly Changer.exe
FileVersion: 76.19.3.6
CompanyName: xe1axe2dxe35xe17xe2dxe33xe03xe32xe2bxe22xe37xe30xe46xe31xe2bxe30xe23xe31xe1cxe25xe03xe32xe44xe37xe1bxe21xe43xe27xe14
LegalTrademarks: xe14xe37xe2dxe1bxe17xe21xe31xe49xe1axe07xe30xe17xe14xe2axe46xe2bxe07xe37xe43xe17xe27xe1dxe41xe31xe1dxe46xe21xe35xe27xe1b
Comments: xe44xe1exe33xe2axe48xe03xe34xe21xe1fxe31xe44xe25xe1bxe1axe22xe48xe1fxe01xe2axe23xe32xe32xe31xe30xe2axe40xe27xe1dxe35
ProductName: xe14xe23xe33xe30xe03xe21xe43xe41xe37xe01xe41xe2bxe37xe1cxe1axe44xe2axe37xe1bxe25xe23xe27xe46xe43xe48xe30xe30xe14xe2d
ProductVersion: 76.19.3.6
FileDescription: xe22xe1axe2dxe1dxe30xe48xe1exe48xe44xe22xe35xe23xe2axe46xe49xe27xe30xe1axe49xe22xe07xe1bxe23xe48xe44xe1exe43xe21xe01
OriginalFilename: Assembly Changer.exe

Generik.NFOQWKE also known as:

K7AntiVirusRiskware ( 0040eff71 )
MicroWorld-eScanTrojan.GenericKD.40740755
ALYacTrojan.GenericKD.40740755
CylanceUnsafe
CrowdStrikemalicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3f471e
TrendMicroTROJ_GEN.R002C0DKB18
NANO-AntivirusTrojan.Win32.Generik.fjzgzd
CyrenW32/Trojan.XGCR-1535
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.NFOQWKE
AvastWin32:Malware-gen
GDataMSIL.Backdoor.Bladabindi.93FZLY
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderTrojan.GenericKD.40740755
Ad-AwareTrojan.GenericKD.40740755
SophosMal/Generic-S
F-SecureTrojan.GenericKD.40740755
Invinceaheuristic
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftTrojan.Agent (A)
SentinelOnestatic engine – malicious
Endgamemalicious (high confidence)
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Generic.D26DA793
AegisLabTrojan.MSIL.Bladabindi.4!c
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=99)
MalwarebytesBackdoor.Agent.ASMGen
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKB18
FortinetW32/Bladabindi!tr.bdr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.633

How to remove Generik.NFOQWKE?

Generik.NFOQWKE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment