Categories: Malware

Win32/GenKryptik.ECFM malicious file

The Win32/GenKryptik.ECFM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.ECFM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Win32/GenKryptik.ECFM?


File Info:

crc32: F9BB9CDAmd5: 7ac2aae4c10db3a2d8ca7b645a30ee75name: lc632205244.exesha1: 7d432cd1be783e46a5133586bc41d2cd769a4b0dsha256: 60d8175e0a4a6e115ed79800717cc27bd3e8d8b88af2f81823623c1b3fead089sha512: 948abbf612bdd45b328584351c74abcbf94e3aed74b9dc2d8f2bc215b96462a8a631bd1a3fae401ce650bf4b412922635f48da871f46878090c161359cf09318ssdeep: 6144:reeqOehy0o9z+dfMfpwZZZZwTzkF5+ZymSRlndx:qVjt8Pfi5+ZIXtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002InternalName: DShowEncoderFileVersion: 1, 0, 0, 76CompanyName: LegalTrademarks: ProductName: Application DShowEncoderProductVersion: 1, 0, 0, 76FileDescription: Application MFC DShowEncoderOriginalFilename: DShowEncoder.EXETranslation: 0x040c 0x04b0

Win32/GenKryptik.ECFM also known as:

FireEye Generic.mg.7ac2aae4c10db3a2
McAfee GenericRXAA-AA!7AC2AAE4C10D
AegisLab Trojan.Win32.Generic.4!c
BitDefender Trojan.GenericKD.42262414
TrendMicro TrojanSpy.Win32.EMOTET.SMD6.hp
APEX Malicious
ClamAV Win.Trojan.Emotet-7546865-0
GData Trojan.GenericKD.42262414
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/starter.ali1000037
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Endgame malicious (moderate confidence)
F-Secure Trojan.TR/AD.Emotet.frzdc
DrWeb Trojan.DownLoader32.49099
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
Emsisoft Trojan.GenericKD.42262414 (B)
Webroot W32.Trojan.Emotet
Avira TR/AD.Emotet.frzdc
MAX malware (ai score=87)
Microsoft Trojan:Win32/Emotet.ARJ!MTB
Arcabit Trojan.Generic.D284DF8E
ZoneAlarm UDS:DangerousObject.Multi.Generic
AhnLab-V3 Malware/Win32.RL_Generic.R313570
Ad-Aware Trojan.GenericKD.42262414
Malwarebytes Trojan.Emotet
ESET-NOD32 a variant of Win32/GenKryptik.ECFM
SentinelOne DFI – Suspicious PE
Fortinet W32/GenKryptik.ECEO!tr
Paloalto generic.ml

How to remove Win32/GenKryptik.ECFM?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “TrojanDownloader:Win32/Beebone.IR”?

The TrojanDownloader:Win32/Beebone.IR is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

How to remove “Malware.AI.3856697558”?

The Malware.AI.3856697558 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

BrowseFox.Adware.AdInjector.DDS information

The BrowseFox.Adware.AdInjector.DDS is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Win32:AutoRun-BSW [Wrm] malicious file

The Win32:AutoRun-BSW [Wrm] is considered dangerous by lots of security experts. When this infection is…

1 hour ago

About “MSIL/TrojanDownloader.Agent.QQN” infection

The MSIL/TrojanDownloader.Agent.QQN is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.975225574 removal

The Malware.AI.975225574 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago