Malware

Generik.NWFAUBA (file analysis)

Malware Removal

The Generik.NWFAUBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NWFAUBA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Anomalous file deletion behavior detected (10+)
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Binary compilation timestomping detected

How to determine Generik.NWFAUBA?


File Info:

name: A384EB6AFEAEFEAA92E3.mlw
path: /opt/CAPEv2/storage/binaries/dfbf0003347e4d4b054e6be769ab74bd2b04780df5ffade22196381992f2f499
crc32: 37DE5CE4
md5: a384eb6afeaefeaa92e38d04d9c2d3e4
sha1: c3d93de9daba54f522c1e2ab0d8920ece2261eab
sha256: dfbf0003347e4d4b054e6be769ab74bd2b04780df5ffade22196381992f2f499
sha512: c26667f449e15c31e8912acc7193177376ce5d43435d3920f5afd2295dbe74596bff9d4edc97c337da074f51932605c4d691a8010ba18a6862c4a51e277758e5
ssdeep: 3072:kahKyd2n31u5GWp1icKAArDZz4N9GhbkrNEkFJ4g0:kahOap0yN90QEl
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T109045B0563F4516AF4F66BB499F202935A32BC619F7582AF1284D57E0E33AC0E931F27
sha3_384: bc2ca7fb7f832caa5d35127f59fc8659f721643ba14ad19071fd6783584f9a26f6d61077a38052fd7fc6558b1cf35c79
ep_bytes: 4883ec28e85b0700004883c428e90600
timestamp: 2062-07-25 12:18:00

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.19041.561 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.19041.561
Translation: 0x0809 0x04b0

Generik.NWFAUBA also known as:

LionicTrojan.BAT.KillFiles.4!c
MicroWorld-eScanTrojan.GenericKD.46416091
FireEyeTrojan.GenericKD.46416091
McAfeeRDN/Generic Del.x
CylanceUnsafe
SangforTrojan.BAT.KillFiles.gv
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:BAT/KillFiles.1a459534
K7GWRiskware ( 0040eff71 )
CyrenW64/Trojan.JEJX-7053
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.NWFAUBA
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.BAT.KillFiles.gv
BitDefenderTrojan.GenericKD.46416091
NANO-AntivirusTrojan.Dos.KillFiles.drlfbb
TencentBat.Trojan.Killfiles.Llqq
Ad-AwareTrojan.GenericKD.46416091
SophosMal/Generic-S
ZillyaTrojan.KillFiles.BAT.82
McAfee-GW-EditionBehavesLike.Win64.Dropper.ch
EmsisoftTrojan.GenericKD.46416091 (B)
GDataTrojan.GenericKD.46416091
Antiy-AVLTrojan/Generic.ASScript.8A3BA
ArcabitTrojan.Generic.D2C440DB
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.KillFiles.C4511562
ALYacTrojan.GenericKD.46416091
MAXmalware (ai score=83)
MaxSecureTrojan.Malware.8444319.susgen
FortinetMalicious_Behavior.SB
AVGFileRepMalware

How to remove Generik.NWFAUBA?

Generik.NWFAUBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment