Malware

Generik.NIWVBYR information

Malware Removal

The Generik.NIWVBYR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NIWVBYR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:6039
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ping3.teamviewer.com
master13.teamviewer.com

How to determine Generik.NIWVBYR?


File Info:

crc32: E653A2DE
md5: 9601e4538b55b1dc2031ae9ffd05abff
name: upload_file
sha1: 8a0cb0674c714520a2bfe361dbfb9344c946efd3
sha256: 818879e025de0edf6dc27fc9df7b763bec9ebac29952e6dda015f05307349520
sha512: e52a663bfdaeec104b6a4c1b677f3244655d9afea4dab7aea1c892104a7a0911c2ffc8b8a06f201d0bb2133bfbdbce99287687bbd55d7d5f8a760b67434c292e
ssdeep: 98304:S5hUDsUlacXe6kxoIewFLlJIgoRTyIos6VAdVkMnwIYDa6KseyCUMXS:mhUDf0cXrkxoTu5Oos6+n3nJYZPMi
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

LegalCopyright: Copyright 1984-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
:
FileVersion: 19.8.20071.303822
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Acrobat Reader DC
ProductVersion: 19.8.20071.303822
FileDescription: Adobe Acrobat Reader DC
Translation: 0x0409 0x04e4

Generik.NIWVBYR also known as:

DrWebTrojan.Siggen10.31024
MicroWorld-eScanTrojan.GenericKD.43991606
Qihoo-360Win32/Trojan.Spy.01e
McAfeeArtemis!9601E4538B55
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.TheRat.l!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.43991606
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R067C0WJ620
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.TheRat.jn
AlibabaTrojanSpy:Win32/TheRat.1d926968
NANO-AntivirusTrojan.Win32.TheRat.hxspve
ViRobotTrojan.Win32.Z.Therat.5027950
Ad-AwareTrojan.GenericKD.43991606
EmsisoftTrojan.GenericKD.43991606 (B)
ComodoMalware@#1a733j9lsls1n
F-SecureTrojan.TR/Spy.Agent.lvmtj
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.43991606
SophosMal/Generic-S
IkarusTrojan.Spy.Agent
JiangminTrojanSpy.TheRat.bz
WebrootW32.Trojan.Gen
AviraTR/Spy.Agent.lvmtj
MicrosoftTrojan:Win32/Ymacco.AA45
ArcabitTrojan.Generic.D29F4236
ZoneAlarmTrojan-Spy.Win32.TheRat.jn
GDataTrojan.GenericKD.43991606
VBA32Trojan.Hesv
ALYacTrojan.GenericKD.43991606
MAXmalware (ai score=100)
MalwarebytesTrojan.Dropper
PandaTrj/CI.A
ESET-NOD32a variant of Generik.NIWVBYR
TrendMicro-HouseCallTROJ_GEN.R067C0WJ620
SentinelOneDFI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
MaxSecureTrojan.Malware.107607391.susgen

How to remove Generik.NIWVBYR?

Generik.NIWVBYR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment