Malware

What is “Generik.NMKPQMI”?

Malware Removal

The Generik.NMKPQMI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NMKPQMI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Generik.NMKPQMI?


File Info:

name: CA602FF188B3B392598E.mlw
path: /opt/CAPEv2/storage/binaries/d9d256b781f9f95d3415c9d0b7f65715071fb140b07d66f7b8ed1f632929ddd6
crc32: BFA0EF18
md5: ca602ff188b3b392598e8707fec5d6d6
sha1: 2520fd6434657fe7e94ccd9f5c5f1d4b2962cd37
sha256: d9d256b781f9f95d3415c9d0b7f65715071fb140b07d66f7b8ed1f632929ddd6
sha512: 9a1c49439a5214f3c245f8334c4041f8265900bff6120f130fd42e056fb6d2cfe51d4356c724c465459ea3322675ab99362830ce4255e3c983ef883c0be5926b
ssdeep: 49152:LtpjhD6pttlbABJdpnfc4XFNldkTMutuXpvYMMpb84yfw0QT13GKkxHknnfc4XFI:v1olbUpXY3yw0QT13jX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF16CF263394C416D1BE0274887287AD07B1FE279B26DB8F29C9346E5DB1781DF22367
sha3_384: 660c51de512662e659e4d1bcadf11e6bb52228aaf1c05ecdc65ee495acb2037dfa6cd4c75cf787a41e495e5e8a424d7a
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-11-12 16:32:38

Version Info:

Translation: 0x0000 0x04b0
Comments: LabTech Silent Installer.
CompanyName: LabTech Software, LLC.
FileDescription: LTSilent
FileVersion: 31.1.3944.17813
InternalName: LTSilent.exe
LegalCopyright: Copyright© 2005-2010 LabTech Software, LLC
OriginalFilename: LTSilent.exe
ProductName: LabTech MSP
ProductVersion: 3.0
Assembly Version: 31.1.3944.17813

Generik.NMKPQMI also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.27424
MicroWorld-eScanTrojan.GenericKD.38083417
FireEyeGeneric.mg.ca602ff188b3b392
McAfeeArtemis!CA602FF188B3
CylanceUnsafe
ZillyaTrojan.Betabot.Win32.9
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Betabot.91d12b81
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
CyrenW32/A-9050270e!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NMKPQMI
TrendMicro-HouseCallTROJ_GEN.R002C0GKO21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Betabot.k
BitDefenderTrojan.GenericKD.38083417
NANO-AntivirusTrojan.Win32.RiskGen.dchwot
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.1149766a
Ad-AwareTrojan.GenericKD.38083417
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GKO21
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.38083417 (B)
IkarusTrojan.Rogue.11181390
JiangminTrojan.Betabot.g
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1108896
MAXmalware (ai score=83)
MicrosoftTrojan:Script/Phonzy.A!ml
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Betabot.4398081
GDataMSIL.Trojan.BSE.1RBQ0XA
CynetMalicious (score: 99)
VBA32Trojan.Betabot
ALYacTrojan.GenericKD.38083417
MalwarebytesMalware.AI.3709619103
APEXMalicious
YandexRiskware.RemoteAdmin!sY+0qOUYQbU
SentinelOneStatic AI – Malicious PE
eGambitnot-a-virus:remoteAdmin.VNC.Variant
FortinetMSIL/Generic.AP.BFC6E2!tr
AVGWin32:Malware-gen
Cybereasonmalicious.434657
PandaTrj/CI.A

How to remove Generik.NMKPQMI?

Generik.NMKPQMI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment