Malware

Win32/GenKryptik.CGZB removal

Malware Removal

The Win32/GenKryptik.CGZB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CGZB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.CGZB?


File Info:

crc32: 29F31D0A
md5: ccbbef6221ebcc846335ba16cfd4c84f
name: CCBBEF6221EBCC846335BA16CFD4C84F.mlw
sha1: a7fee83e76f827b11a851a685d0537b276811f81
sha256: 3836dd91f6915d5dd12b69a8fdc6fe9181f41e1da4dcf1bb5d92ab5b4d1fd778
sha512: 04a39cf190635c541bfb2974144fdfe0c424f89be042bbe14d61659dadde62042c72d45a0381c417456f84922d1302c3e3933df47506a65857e846a6883f567d
ssdeep: 24576:B4I+X78euc1ybpspS/qx6MI6OW10DQxxTcp0JK:Sjr8TcNISpHP+WK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2007-2015 DivX, LLC
InternalName: Dmains Shve
FileVersion: 7.3.5.809
CompanyName: DivX, LLC
FileDescription: Declarations Practices Automatically Avoid Andy
LegalTrademarks: (C) 2007-2015 DivX, LLC
ProductName: Dmains Shve
ProductVersion: 7.3.5.809
PrivateBuild: 7.3.5.809
Translation: 0x0409 0x04b0

Win32/GenKryptik.CGZB also known as:

K7AntiVirusTrojan ( 0053987b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.148211
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Shade.cf0f9c29
K7GWTrojan ( 0053987b1 )
Cybereasonmalicious.221ebc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CGZB
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Shade.ouq
BitDefenderTrojan.GenericKD.31154806
NANO-AntivirusTrojan.Win32.GenKryptik.fgfxom
MicroWorld-eScanTrojan.GenericKD.31154806
TencentMalware.Win32.Gencirc.114d2a00
Ad-AwareTrojan.GenericKD.31154806
SophosMal/Generic-S
ComodoMalware@#1w6ck211bs8i
F-SecureHeuristic.HEUR/AGEN.1129573
BitDefenderThetaGen:NN.ZexaE.34058.hr0@a84YyCdi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Shade.R002C0PHE21
McAfee-GW-EditionGenericR-NHG!CCBBEF6221EB
FireEyeGeneric.mg.ccbbef6221ebcc84
EmsisoftTrojan.GenericKD.31154806 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Shade.my
AviraHEUR/AGEN.1129573
eGambitUnsafe.AI_Score_94%
ZoneAlarmTrojan-Ransom.Win32.Shade.ouq
GDataTrojan.GenericKD.31154806
TACHYONTrojan/W32.ZBot.1167360
AhnLab-V3Trojan/Win32.ZBot.C2646108
Acronissuspicious
VBA32BScope.TrojanRansom.Shade
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4018736323
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Shade.R002C0PHE21
YandexTrojan.GenAsa!aY1bynbZImY
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GKUA!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Shade.HwkAEpsA

How to remove Win32/GenKryptik.CGZB?

Win32/GenKryptik.CGZB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment