Malware

Generik.RIPCAX removal tips

Malware Removal

The Generik.RIPCAX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generik.RIPCAX virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • CAPE detected the PyInstaller malware family

How to determine Generik.RIPCAX?


File Info:

name: 8CA69B174A15F9CA24EA.mlw
path: /opt/CAPEv2/storage/binaries/61994615b38db28bdc950e59ca0ad45385ee4d14514fff511ad2d6a44b973528
crc32: 44329D65
md5: 8ca69b174a15f9ca24ea51c442ffcce7
sha1: d77a626c012b96b591866dbc8fdaa2421f565e77
sha256: 61994615b38db28bdc950e59ca0ad45385ee4d14514fff511ad2d6a44b973528
sha512: 1534b3dd3ce0bc90c95b2b38b0106564df9df3dbd971b32c08f27043488cda15c9c7253153f30c8f16993b5b5db3f589eb9e8fb7484ac8992150ed943bdd6af3
ssdeep: 98304:+p80GCnfTjFzLQSF2x+yAiWMJBYHXgHpAJhglerJsNfG8dmdi:+pqaLZex+yAiWfXUpAJhglVNfG8AI
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1C816339067820EF9F863173EC856C506DAB57C279360C28B07E08B336F636E4AD6E755
sha3_384: 6e2f0f17b93ce3d1274e3344b78024a68bc48de6f8df06ca69a1c04bb1fc23cd95db9c400c39a07491b18d43c72ee3dd
ep_bytes: 4883ec28e8070500004883c428e96afe
timestamp: 2022-09-24 00:15:56

Version Info:

0: [No Data]

Generik.RIPCAX also known as:

LionicTrojan.Win32.UAC.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.62608511
FireEyeTrojan.GenericKD.62608511
McAfeeArtemis!8CA69B174A15
MalwarebytesSpyware.PasswordStealer.Python
VIPRETrojan.GenericKD.62608511
SangforExploit.Win32.Uac.Vlz9
AlibabaExploit:Application/Generic.a91d2ecf
CyrenW64/ABRisk.IMLR-7984
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.RIPCAX
KasperskyExploit.Win32.UAC.inz
BitDefenderTrojan.GenericKD.62608511
AvastWin64:Malware-gen
TencentWin32.Trojan.FalseSign.Ngil
Ad-AwareTrojan.GenericKD.62608511
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.62608511 (B)
GDataTrojan.GenericKD.62608511
GoogleDetected
AviraEXP/UAC.kxkjt
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D3BB547F
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32Exploit.UAC
ALYacTrojan.GenericKD.62608511
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CJ922
RisingExploit.UAC!8.107CD (CLOUD)
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
PandaTrj/Chgt.AA

How to remove Generik.RIPCAX?

Generik.RIPCAX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment