Malware

Win32/GenKryptik.CMCT removal

Malware Removal

The Win32/GenKryptik.CMCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CMCT virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
config.cqyzzkj.cn

How to determine Win32/GenKryptik.CMCT?


File Info:

crc32: 9B52D1D1
md5: f94efe4c4ac6eedd7d1a67a12b59ff8a
name: xbdtfences4310v1427.exe
sha1: 52abc1ca0eb5727bec7ee7981b4d8daeb415a0cf
sha256: dec7319080cfc187e23296e0d366b02a45f69856806682dee931ac365a9e0cf6
sha512: 16867fd5b5a1b73f6b7f9c7d0721b1a68096d8bb6fdee8edf2ddb8011d51c945b809ffc086d85946a609c9af52328d9196970be97b0a97819c6d40798c0cc272
ssdeep: 196608:0GKm5pCdKOXkj8qUW7ZtMa7rKzkwsE5i+uSzCznq9:mm5pCdnG8q7ttQzhsb+7zSq9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Chongqing Yizhenze Technology Co., Ltd. 2019
InternalName: XiaobeiDesktopSetup
FileVersion: 1.4.2.7
CompanyName: Chongqing Yizhenze Technology Co., Ltd.
ProductName: x5c0fx8d1dx684cx9762x6574x7406x841dx535cx7248
ProductVersion: 1.4.2.7
FileDescription: x5c0fx8d1dx684cx9762x6574x7406x841dx535cx7248x5b89x88c5x7a0bx5e8f
OriginalFilename: XiaobeiDesktopSetup.exe
Translation: 0x0804 0x04b0

Win32/GenKryptik.CMCT also known as:

MicroWorld-eScanTrojan.GenericKD.41201778
FireEyeTrojan.GenericKD.41201778
ZillyaDownloader.Chindo.Win32.963
BitDefenderTrojan.GenericKD.41201778
K7GWTrojan ( 0053d4641 )
NANO-AntivirusTrojan.Win32.GenKryptik.fnjdnp
ESET-NOD32a variant of Win32/GenKryptik.CMCT
TrendMicro-HouseCallTROJ_GEN.R04AH0CCJ19
KasperskyTrojan-Downloader.Win32.Chindo.bza
AlibabaTrojan:Win32/GenKryptik.a5bfc244
TencentWin32.Trojan-downloader.Chindo.Eddu
Ad-AwareTrojan.GenericKD.41201778
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1038634
DrWebTrojan.DownLoader27.33298
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
EmsisoftTrojan.GenericKD.41201778 (B)
IkarusTrojan-Downloader.Win32.Chindo
GDataWin32.Trojan.Agent.RV7OYG
AviraHEUR/AGEN.1038634
ArcabitTrojan.Generic.D274B072
ZoneAlarmTrojan-Downloader.Win32.Chindo.bza
McAfeeArtemis!F94EFE4C4AC6
MAXmalware (ai score=87)
VBA32BScope.TrojanDownloader.Chindo
RisingDownloader.Chindo!8.436 (CLOUD)
YandexTrojan.GenKryptik!
eGambitUnsafe.AI_Score_93%
FortinetW32/GenKryptik.CMCT!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Win32/GenKryptik.CMCT?

Win32/GenKryptik.CMCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment