Malware

Generik.NIMMPRE (file analysis)

Malware Removal

The Generik.NIMMPRE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NIMMPRE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

api.ipify.org
caperesto.com
gru77.ru

How to determine Generik.NIMMPRE?


File Info:

crc32: 88102D5F
md5: 4dd91b29615ee978f1c13a08a2b2299e
name: 4DD91B29615EE978F1C13A08A2B2299E.mlw
sha1: 9a5741f2aa654edc45c6a3fcabc0f260326e90bb
sha256: 989bb0930dd9a2c1aff5a7e29d6a3b2a425eae5b097495c8de37cda09f5e5c9d
sha512: 1e0350d3adb3128ed2ab1e2fefc98df001b49f24f26fa96a4443e9839d52463f7a3e5affa70ff5a8d90f27a3f1f240ba628d9186c22ca2924362477615450b9a
ssdeep: 3072:mojtg6jca6iMdxkpYQcqIxLuuwhb0NjTyLsrq9QDLWNHKqx:mQinIRHLgDU
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generik.NIMMPRE also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Chanitor.59
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NIMMPRE
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Bsymem.zzu
BitDefenderTrojan.GenericKD.36800357
MicroWorld-eScanTrojan.GenericKD.36800357
Ad-AwareTrojan.GenericKD.36800357
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Vundo.ch
FireEyeGeneric.mg.4dd91b29615ee978
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmTrojan.Win32.Bsymem.zzu
GDataWin32.Trojan.Kryptik.ETDP7T
McAfeeRDN/Generic.com
MAXmalware (ai score=85)
RisingTrojan.Injector!1.D40E (CLOUD)
IkarusWin32.Outbreak
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Generik.NIMMPRE?

Generik.NIMMPRE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment