Malware

Generik.NXBGNBE removal guide

Malware Removal

The Generik.NXBGNBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.NXBGNBE virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generik.NXBGNBE?


File Info:

name: A86EF3E84EFF7F5D5EF0.mlw
path: /opt/CAPEv2/storage/binaries/63e75c73fb195a4d9a7d74bea5a82fd97898ef5af650dd28cb2d6d69d748ca41
crc32: 1F664374
md5: a86ef3e84eff7f5d5ef007d427ea84e1
sha1: aa394b660b1a75d6b1082837efb17ae000153010
sha256: 63e75c73fb195a4d9a7d74bea5a82fd97898ef5af650dd28cb2d6d69d748ca41
sha512: 71681a7688f867f4d3f3f04c12ddb8e950389cb20329e0995965887868df659c3e3d989ce6bf4ac79873d58ddef457bc693b0ed6b25cd3da8a43d14a42113735
ssdeep: 98304:kN74LS6Czy5280eIMvG/V1XdVtHNdxtTCfgi/7:UULLCzQ0eIMvG/V1X3tHNdxtTCfgi/7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C716E5166B218157C8A397F18A6A79C01658BA3438F0E9DB31DC0FDD2777B427E2670E
sha3_384: 06aa063b430e9222256daf1383145ddcd655611ee60e488fa190fd4f1fc760e8a2fe3ff7784345aedf857225d71488cd
ep_bytes: c6050800800000e8b4ffffffb8805581
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Generik.NXBGNBE also known as:

BkavW32.Common.0116E0EB
LionicWorm.Win32.Generic.o!c
CAT-QuickHealTrojan.Cosmu
McAfeeArtemis!A86EF3E84EFF
MalwarebytesMalware.Heuristic.1006
ZillyaTrojan.Cosmu.Win32.14759
SangforTrojan.Win32.Cosmu.V65b
K7AntiVirusTrojan ( 0000000c1 )
AlibabaMalware:Win32/Dorpal.ali1000029
K7GWTrojan ( 0000000c1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.2
ESET-NOD32a variant of Generik.NXBGNBE
KasperskyTrojan.Win32.Cosmu.dhqr
NANO-AntivirusTrojan.Win32.Cosmu.hkcokg
AvastWin32:Malware-gen
TencentWin32.Trojan.Cosmu.Pgil
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
Antiy-AVLTrojan/Win32.Tgenic
ZoneAlarmTrojan.Win32.Cosmu.dhqr
MicrosoftTrojan:Win32/Suloc.A
GoogleDetected
VBA32Trojan.Cosmu
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CI923
RisingTrojan.Cosmu!8.2B2 (TFE:5:xxp9u1cfJ1I)
YandexTrojan.Cosmu!GCE+ZVv34Qk
FortinetW32/Malicious_Behavior.VEX
BitDefenderThetaGen:NN.ZexaF.36662.@xX@a4ZWFnci
AVGWin32:Malware-gen
Cybereasonmalicious.60b1a7
DeepInstinctMALICIOUS

How to remove Generik.NXBGNBE?

Generik.NXBGNBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment