Malware

Generik.NRLGVBE malicious file

Malware Removal

The Generik.NRLGVBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NRLGVBE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • CAPE detected the CryptBot malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Generik.NRLGVBE?


File Info:

name: 238D9C58D1FB7E4FF30E.mlw
path: /opt/CAPEv2/storage/binaries/a42a167fa0dd4cfb1d3f455e8f3eec852428dcafbf8cff0f7f1ce5ebd83d1016
crc32: 08254C2A
md5: 238d9c58d1fb7e4ff30e3a6c3391a7d7
sha1: 33b8db22723bdfd6944138dc6f2a2913a3514f27
sha256: a42a167fa0dd4cfb1d3f455e8f3eec852428dcafbf8cff0f7f1ce5ebd83d1016
sha512: 5130b24ddb762608f8943b4a2b73a96cdb369eaa2d6fecf74f6cc1d5a5aaf154c7adc698f9923e1f98c041f095d101b7cb1c2d03861fc9b3b6231fe8e34354ed
ssdeep: 12288:SCusUdv19yAENIpqDynb+i8MWzSlsTmVPd6:7u9WAUJD29lRVPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175F46CC0FE13CB0BF358D03984176BE24A9939A67BA1BCFDB8DDF9AB9D59520150110B
sha3_384: c80e9916cc3cd03c80da4d79e6ad8c786af84932ea11efa5bf85e89f65659b103ec96d3a1261ce98646fe021dc4676eb
ep_bytes: 31ffff15db9d490089c2685e7f2f4968
timestamp: 2021-11-27 01:54:29

Version Info:

CompanyName: Avira Operations GmbH & Co. KG
FileDescription: License Manager
FileVersion: 15.0.16.273
InternalName: licmgr.exe
LegalCopyright: Copyright © 2016 Avira Operations GmbH & Co. KG and its Licensors
OriginalFilename: licmgr.exe
ProductName: Avira Product Family
ProductVersion: 15.0.16.273
Translation: 0x0000 0x04b0

Generik.NRLGVBE also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.56483
CynetMalicious (score: 100)
FireEyeGeneric.mg.238d9c58d1fb7e4f
CylanceUnsafe
K7AntiVirusTrojan ( 0058b0451 )
AlibabaTrojan:Win32/SelfDel.44383bf1
K7GWTrojan ( 0058b0451 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NRLGVBE
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SelfDel.hvnk
AvastWin32:TrojanX-gen [Trj]
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Script/Phonzy.B!ml
GridinsoftRansom.Win32.Sabsik.sa
GDataWin32.Trojan-Stealer.CoinStealer.F0G6D3
Acronissuspicious
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazoBJSohGkx8g2oiouOpnfHu)
YandexTrojan.Agent!MxAltOW1cTg
IkarusTrojan.SuspectCRC
eGambitPE.Heur.InvalidSig
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.2723bd

How to remove Generik.NRLGVBE?

Generik.NRLGVBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment