Malware

Generik.NOYWEPR (file analysis)

Malware Removal

The Generik.NOYWEPR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NOYWEPR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generik.NOYWEPR?


File Info:

name: 1D552341451DE54BDBB6.mlw
path: /opt/CAPEv2/storage/binaries/04bdb9db0ebfee996539edb42e35cbde983fbb762b027c27e5f4d569c0acb94b
crc32: 86A7CEB0
md5: 1d552341451de54bdbb6c1699ea49563
sha1: 853fa925ab330619cab8af9c4d2be1ae038d4273
sha256: 04bdb9db0ebfee996539edb42e35cbde983fbb762b027c27e5f4d569c0acb94b
sha512: ae0ec55edd6d16eb185f3b2158799fdee1fdafb271d10b5fe2ce4c8f2ecc0734e1d72f24373a676bc95ee1834fa67ff57ebafc3d31aa03821bac9cfee874b878
ssdeep: 98304:3htV6zD4oa2B50JC/k4jCNmq/aMWm3+skEmvg8hCFgrPi+rEDvsVsFOOIj4GTMP:xJ2B0Cs4eAArmHgwhZrEDvYkfGTMP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1004633A6D90D54F1F0E1D9746A26A5340C77F6F3B1783A2C34DD2A649F00EB268B3279
sha3_384: a054e3ab987c03522bc276bfb70ec1490bddb9b042439dcf56d287343e7941583063b837348836a93701dc50f22f91af
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: SoftOrbits
FileDescription: Picture Doctor Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Generik.NOYWEPR also known as:

LionicTrojan.Win32.Adload.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.67204132
FireEyeTrojan.GenericKD.67204132
SkyhighBehavesLike.Win32.ObfuscatedPoly.tc
McAfeeArtemis!1D552341451D
Cylanceunsafe
SangforAdware.Win32.AdLoad.Vn0u
AlibabaAdWare:Win32/AdLoad.540d3b0c
Cybereasonmalicious.1451de
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.NOYWEPR
APEXMalicious
AvastNSIS:Adware-AEK [Adw]
KasperskyTrojan-Downloader.Win32.Adload.tovp
BitDefenderTrojan.GenericKD.67204132
TencentWin32.Trojan-Downloader.Adload.Ozfl
EmsisoftTrojan.GenericKD.67204132 (B)
F-SecureHeuristic.HEUR/AGEN.1333117
DrWebTrojan.DownLoader44.15730
VIPRETrojan.GenericKD.67204132
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
MAXmalware (ai score=88)
JiangminTrojanDownloader.Adload.aixi
AviraHEUR/AGEN.1333117
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Generic.D4017424
ZoneAlarmTrojan-Downloader.Win32.Adload.tovp
GDataTrojan.GenericKD.67204132
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.67204132
MalwarebytesAdware.DownloadAssistant
MaxSecureTrojan.Malware.208522530.susgen
FortinetW32/Agent.SLC!tr
AVGNSIS:Adware-AEK [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Generik.NOYWEPR?

Generik.NOYWEPR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment