Malware

About “Win32/GenKryptik.DUXJ” infection

Malware Removal

The Win32/GenKryptik.DUXJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.DUXJ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.DUXJ?


File Info:

crc32: BC527C0E
md5: 285e57297f578e565dc814301149edbf
name: 285E57297F578E565DC814301149EDBF.mlw
sha1: 1b7a5c582d56646a0e51b3296e69e9f61b3ffa0d
sha256: 197163b6eb2114f3b565391f43b44fb8d61531a23758e35b11ef0dc44d349e90
sha512: a256715cfc20b34afe9b0075f02d45348c8bfc3d15ad8ef8ae81634b83997044aa6395a57df2a0bed315cf9a12e5c30494ebe758130371b5c597e6329a748204
ssdeep: 3072:3JAbotnxd8Rt+Q+i17+H3UQ+CYZ4H/dWgG+9Q:iboNIn+I+51/g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) Agreeface HEALTHCAREfirst, 2018. All rights reserved Bat
InternalName: Rep.exe
FileVersion: 15.3.47.30
CompanyName: Agreeface HEALTHCAREfirst
OriginalFilename2: Rep.exe
LegalTrademarks: Agreeface HEALTHCAREfirst
ProductName: Agreeface HEALTHCAREfirst Told
FileDescription: Agreeface HEALTHCAREfirst
OriginalFilename: Rep.exe
Translation: 0x0409 0x04e4

Win32/GenKryptik.DUXJ also known as:

LionicTrojan.Win32.Cridex.7!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.45076
ALYacSpyware.Banker.Dridex
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.52746
SangforSpyware.Win32.Cridex.pou
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/Cridex.93ed1681
K7GWTrojan ( 0055953b1 )
K7AntiVirusTrojan ( 0055953b1 )
CyrenW32/Trojan.CHNU-3238
SymantecTrojan Horse
ESET-NOD32a variant of Win32/GenKryptik.DUXJ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Banker.Win32.Cridex.pou
BitDefenderGen:Heur.Pack.Emotet.6
NANO-AntivirusTrojan.Win32.Cridex.hqbjbt
MicroWorld-eScanGen:Heur.Pack.Emotet.6
TencentWin32.Trojan-banker.Cridex.Hqvu
Ad-AwareGen:Heur.Pack.Emotet.6
SophosMal/Generic-S
ComodoMalware@#3936bmssuwjig
BitDefenderThetaGen:NN.ZexaF.34170.ku0@a05fPIbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WGB21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.285e57297f578e56
EmsisoftGen:Heur.Pack.Emotet.6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Cridex.aev
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30C22AB
MicrosoftRansom:Win32/StopCrypt!ml
ArcabitTrojan.Pack.Emotet.6
ZoneAlarmTrojan-Banker.Win32.Cridex.pou
GDataGen:Heur.Pack.Emotet.6
AhnLab-V3Trojan/Win.Agent.R418935
McAfeeArtemis!285E57297F57
MAXmalware (ai score=86)
VBA32TrojanBanker.Cridex
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WGB21
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.74474672.susgen
FortinetW32/Gozi.GET!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/GenKryptik.DUXJ?

Win32/GenKryptik.DUXJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment