Malware

What is “Win32/GenKryptik.CENJ”?

Malware Removal

The Win32/GenKryptik.CENJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CENJ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
hi.baidu.com
infoflow.baidu.com
ocsp.globalsign.com
ocsp2.globalsign.com
a.tomx.xyz

How to determine Win32/GenKryptik.CENJ?


File Info:

crc32: 8A202C17
md5: 108156615f13f94750d00d0526a22c73
name: 108156615F13F94750D00D0526A22C73.mlw
sha1: 02db2b70399efe4f627496e3e4a2f5c5f50abb63
sha256: 1599b0f42eb04f570233a337b343e996063f7d515e90ad9c9fd196e91f0476d3
sha512: ef88e467f99decbdaf17affd2577cf44693662d79f5b52aebf66f449c8d1a594f0d4fa58b889952c020e67ebde9b8b80fafe43ab8c15f7523eddb4cf1103f5a9
ssdeep: 768:V8Ur9BWErx0YCPuRAj0U1hkp26vypDkmODmHQLf0eE9SbRBL4Ibz:dZoEV0JuRUFyMOaHQLf0ek4RBl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1984-2008 Adobe Systems Incorporated and its licensors. All rights reserved.
FileVersion: 9.0.0.2008061200
CompanyName: Adobe Systems Incorporated
Comments:
ProductName: Adobe Acrobat
ProductVersion: 9.0.0.2008061200
FileDescription: Adobe Acrobat SpeedLauncher
OriginalFilename: AcroSpeedLaunch.exe
Translation: 0x0409 0x04e4

Win32/GenKryptik.CENJ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056d5f51 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Siggen.54
CynetMalicious (score: 99)
ALYacGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi
CylanceUnsafe
ZillyaTrojan.XPACK.Win32.78
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/GenKryptik.b39ecd75
K7GWTrojan ( 0056d5f51 )
Cybereasonmalicious.15f13f
CyrenW32/A-8316572d!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CENJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi
NANO-AntivirusTrojan.Win32.Patched.eyztvm
MicroWorld-eScanGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi
TencentMalware.Win32.Gencirc.10b13f26
Ad-AwareGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi
SophosML/PE-A + Troj/Patched-BS
ComodoMalware@#qzr45jqshs8c
BitDefenderThetaGen:NN.ZexaF.34170.cu1@aaC5Z!mi
McAfee-GW-EditionRDN/Sality.gen
FireEyeGeneric.mg.108156615f13f947
EmsisoftGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26DBFBA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.ExplorerHijack.cu1@aaC5Z!mi
AhnLab-V3Malware/Win32.Generic.C2666779
Acronissuspicious
McAfeeRDN/Sality.gen
MAXmalware (ai score=80)
VBA32Trojan.Tnega
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
RisingTrojan.Patched!1.B352 (CLASSIC)
IkarusTrojan.Win32.Patched
FortinetW32/Patched.IW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.CENJ?

Win32/GenKryptik.CENJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment