Malware

Win32/GenKryptik.EASK removal instruction

Malware Removal

The Win32/GenKryptik.EASK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EASK virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mardjdf.ug
kjsdtrfuyhgxcv.ru

How to determine Win32/GenKryptik.EASK?


File Info:

crc32: 74F3543D
md5: 0cf4eaf6f59888c47b70b355980cf44f
name: nfsdchgcfcvb.exe
sha1: 76749c2c56057f976962bad79a41de19ef4f21d4
sha256: fe231e75021cd99c711cff304716f70df03ee0076084f7be2a8f37e5ead5b482
sha512: aadce511fe2fc222271755e77e3560e865af8b34e76c84d3d9c22c1a060951f2ea342ffdc5e441a231d30ce0b7cf3a9e4985f02e3f9c235353826435667fae4f
ssdeep: 3072:of3rPBw1u6FBgk3RYXzpFTz7jLFye3dhW+zXSFsjnLLvV9N2GIW4yzc2SUYaz+Mk:of3rPCYXzvz7H0e3zWAfN9NeByz/YKu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) six-gallon 2019
InternalName: teratologies.exe
FileVersion: 1.3.8.1
CompanyName: denaturizing
ProductName: Tacoman
ProductVersion: 7.3.5.2
FileDescription: Phocoena
OriginalFilename: interjectors.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.EASK also known as:

MicroWorld-eScanTrojan.GenericKD.32867480
McAfeeArtemis!0CF4EAF6F598
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.32867480
BitDefenderThetaGen:NN.ZexaF.33558.lu3@aGz3s6ei
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Backdoor.NetWireRC.ZBKS5T
KasperskyTrojan.Win32.NetWire.hut
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.GenKryptik!8.AA55 (TFE:5:qrLlGhfQpnI)
Ad-AwareTrojan.GenericKD.32867480
F-SecureTrojan.TR/AD.NetWiredRc.oppms
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.0cf4eaf6f59888c4
EmsisoftTrojan.GenericKD.32867480 (B)
IkarusWin32.Outbreak
AviraTR/AD.NetWiredRc.oppms
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F58498
ZoneAlarmTrojan.Win32.NetWire.hut
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32BScope.Trojan.Nanocore
ALYacBackdoor.RAT.MSIL.NanoCore
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.EASK
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Malicious_Behavior.VEX
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.18C1.Malware.Gen

How to remove Win32/GenKryptik.EASK?

Win32/GenKryptik.EASK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment