Malware

Win32/GenKryptik.EDRQ removal

Malware Removal

The Win32/GenKryptik.EDRQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EDRQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.EDRQ?


File Info:

crc32: A28ED88A
md5: 5822dd68906fe2fc6e89cf220facc897
name: drop.bin
sha1: bd982c8ff3b9292711cff690de9454bda626c552
sha256: 96523b8624127d27edd616d1ee3767f69dcb56b08b6b6b7ace7e740ed75fdf40
sha512: 2b6e7cb50d3ded25999603034aa21b42650082fb0a362b926f2934544c72224c9a8ec448afb61d001a3fab031b6cd6eddee6218682863217116a1f5486f1e712
ssdeep: 3072:K5y+bnr+O1g5GWp1icKAArDZz4N9GhbkrNEk1b0Yvo6:K5y+bnr+np0yN90QE20Yw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Win32/GenKryptik.EDRQ also known as:

McAfeeRDN/Generic Dropper
CylanceUnsafe
AegisLabTrojan.Win32.Dorifel.b!c
SangforMalware
K7AntiVirusTrojan ( 005613b41 )
K7GWTrojan ( 005613b41 )
Cybereasonmalicious.ff3b92
APEXMalicious
GDataWin32.Trojan.Injector.V27PE5
KasperskyHEUR:Trojan-Dropper.Win32.Dorifel.vho
AlibabaTrojanDropper:Win32/GenKryptik.85914621
ViRobotTrojan.Win32.Z.Dropper.240128.A
TencentWin32.Trojan-dropper.Dorifel.Sunq
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.VB.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.dm
IkarusTrojan-Spy.Agent
CyrenW32/Trojan.KPWY-0432
WebrootW32.Trojan.Gen
AviraTR/Dropper.VB.Gen
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dorifel.vho
MalwarebytesTrojan.Dropper.WXT.Generic
ESET-NOD32a variant of Win32/GenKryptik.EDRQ
RisingDropper.Dorifel!8.31E (CLOUD)
SentinelOneDFI – Suspicious
FortinetW32/GenKryptik.EDRQ!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Dropper.528

How to remove Win32/GenKryptik.EDRQ?

Win32/GenKryptik.EDRQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment