Malware

Should I remove “Generik.NPNKWLQ”?

Malware Removal

The Generik.NPNKWLQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NPNKWLQ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
www.51kly.cn
a.tomx.xyz
ocsp.digicert.com

How to determine Generik.NPNKWLQ?


File Info:

crc32: 3DD6EA90
md5: e61057018d812c06b5bcba390a129b7b
name: zhilong2.8.exe
sha1: 7eb677e0aac32133905343ef1d3ee473c86d2bfe
sha256: 0273d84fbcb7fb49b34c5529794a867cb9731bb7a967c5ff5a9ca71f308b3a4a
sha512: c10fe98ae5a333788f33b037399b34a6bec62f599a940442b74ca423d98403e3067b231fa6943f2168eaf7d5a3450479609a982795ea7643d81ed054841d6821
ssdeep: 49152:e8aSd0MyfTwAl8NYCE3kfJCQne55VJIjvtL1:e20M4TMKCE0fJjn45VJIrN1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x5728x4e8ex516dx70bdxff0cx8bf7x52ffx7834x89e3
FileVersion: 2.8.0.0
CompanyName: x516dx70bd
Comments: x70bdx9f99x6e38x620fx5e73x53f0x5b89x5168x65e0x6bd2x653ex5fc3x5065x5eb7
ProductName: x70bdx9f99x6e38x620fx5e73x53f0
ProductVersion: 2.8.0.0
FileDescription: LREx65d7x4e0bx5e73x53f0x70bdx9f99x6e38x620fx5e10x53f7x5e73x53f0
Translation: 0x0804 0x04b0

Generik.NPNKWLQ also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.41248397
Qihoo-360HEUR/QVM16.0.766F.Malware.Gen
McAfeeArtemis!E61057018D81
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004571581 )
BitDefenderTrojan.GenericKD.41248397
K7GWTrojan ( 004571581 )
Cybereasonmalicious.18d812
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34098.9z0@aKOdTmpb
APEXMalicious
GDataTrojan.GenericKD.41248397
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/VMProtBad-A
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
ZillyaBackdoor.Remcos.Win32.1543
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.e61057018d812c06
EmsisoftTrojan.GenericKD.41248397 (B)
IkarusTrojan.Win32.Crypt
MicrosoftProgram:Win32/Unwaders.C!rfn
ArcabitTrojan.Generic.D275668D
AhnLab-V3Malware/Gen.Generic.C2829520
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.41248397
Ad-AwareTrojan.GenericKD.41248397
ESET-NOD32a variant of Generik.NPNKWLQ
TrendMicro-HouseCallTROJ_GEN.R002H0CBH20
TencentWin32.Trojan.Suspicious.Ahxo
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73910013.susgen

How to remove Generik.NPNKWLQ?

Generik.NPNKWLQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment