Trojan

About “Trojan.Crypt.GENQ” infection

Malware Removal

The Trojan.Crypt.GENQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.GENQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

How to determine Trojan.Crypt.GENQ?


File Info:

crc32: CF409B4B
md5: c5389b1ba4332def2780cc8f3f6b516e
name: C5389B1BA4332DEF2780CC8F3F6B516E.mlw
sha1: a11d54b44bdce16dd7eb8dbf500d047e419fca54
sha256: 5ba3453e36896fc61170020465d67fd9b4d237ade6cdbdd854fc77843f00b4ff
sha512: ddebed9718397f337aa6ad581def26b4b6b9438a363b9d78183fdb32f0179b706ecad480bd4c062c13753a33f09c4844b7a298359b1b4276f21c8144de771192
ssdeep: 3072:BbQMf9RaaFfn9/TK4BcdQwRuvlDSfZ+Vy1Uv:pDaaFfn9/TbWtRuvlefZH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2048
InternalName: Constipation
FileVersion: 190, 50, 125, 157
CompanyName: LCS/Telegraphics, Inc.
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Dispenses Entrenching
SpecialBuild:
ProductVersion: 18, 146, 89, 129
FileDescription: Homestead
OriginalFilename: Experimenting.exe

Trojan.Crypt.GENQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004cdfc81 )
LionicHacktool.Win32.Tpyn.3!c
Elasticmalicious (high confidence)
DrWebTrojan.Sopinar.2
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.56047
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.186871
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004cdfc81 )
Cybereasonmalicious.ba4332
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Sopinar.C
APEXMalicious
AvastWin32:Agent-BAKA [Trj]
KasperskyPacked.Win32.Tpyn
BitDefenderGen:Variant.Symmi.56047
NANO-AntivirusTrojan.Win32.Zbot.dwxesu
MicroWorld-eScanGen:Variant.Symmi.56047
TencentWin32.Packed.Tpyn.Swkm
Ad-AwareGen:Variant.Symmi.56047
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34266.hq0@aKeykynO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
FireEyeGeneric.mg.c5389b1ba4332def
EmsisoftGen:Variant.Symmi.56047 (B)
JiangminPacked.Tpyn.ael
AviraHEUR/AGEN.1120690
Antiy-AVLTrojan/Generic.ASMalwS.140705B
KingsoftWin32.Troj.Zpoot.gn.(kcloud)
MicrosoftTrojan:Win32/Sopinar.D
GDataGen:Variant.Symmi.56047
AhnLab-V3Win-Trojan/Lockycrypt.Gen
McAfeePacked-FP!C5389B1BA433
MAXmalware (ai score=87)
VBA32BScope.Trojan.Sopinar
MalwarebytesTrojan.Crypt.GENQ
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.94 (RDML:3562b1YkCXb/Pq1bQBi4MQ)
YandexTrojan.Zbot!3tjRfMnNVmc
IkarusTrojan.Win32.Sopinar
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bublik.DA!tr
AVGWin32:Agent-BAKA [Trj]
Paloaltogeneric.ml

How to remove Trojan.Crypt.GENQ?

Trojan.Crypt.GENQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment