Malware

Win32/GenKryptik.EELX removal

Malware Removal

The Win32/GenKryptik.EELX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EELX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.EELX?


File Info:

crc32: 0D88E98F
md5: c32da3f75cdd43b5b4a67d68ee969189
name: svchost.exe
sha1: 597e28cb7e235ed244bf0be38e4cfff8b576172c
sha256: 49107c228e38638d3b241bb5c4aa93ef68db20cc0c5a4157e00fc027635418bf
sha512: 87fd347d585c119fd7f9395c334dc2061deb1063f1db4d4b250d5ad97614a0760632655029b6150dc0cbe17024f8c37ca756112b0ad30f32fec85a2cdb12a9ad
ssdeep: 24576:usKwpeVh0gpIkRZMZNi/XPJ3SJknFV23z0+QMN:pH4MZNIJI623zX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Sopcast Copyright (c) 2006-2014
CompanyName: Sopcast
ProductName: Add
ProductVersion: 3.6.8.9
FileDescription: Activities Ancestors Chrmium Emplys Curbside Reverses
OriginalFilename: Add.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.EELX also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.PWS.Siggen2.43680
MicroWorld-eScanTrojan.GenericKD.33289405
FireEyeGeneric.mg.c32da3f75cdd43b5
Qihoo-360Win32/Backdoor.e6a
McAfeeArtemis!C32DA3F75CDD
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33289405
K7GWRiskware ( 0040eff71 )
TrendMicroTrojanSpy.Win32.LOKI.TIOIBYRW
BitDefenderThetaGen:NN.ZexaF.34090.!u0@aS50eIdi
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.33289405
KasperskyBackdoor.Win32.Androm.ttrg
Ad-AwareTrojan.GenericKD.33289405
SophosTroj/Fareit-JRZ
F-SecureTrojan.TR/AD.LokiBot.otvig
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33289405 (B)
IkarusTrojan-Ransom.GandCrab
JiangminTrojan.PSW.MSIL.lse
WebrootW32.Trojan.Gen
AviraTR/AD.LokiBot.otvig
MAXmalware (ai score=83)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FBF4BD
ZoneAlarmBackdoor.Win32.Androm.ttrg
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Malware/Win32.Generic.C3989620
VBA32BScope.TrojanRansom.Foreign
PandaGeneric Malware
ESET-NOD32a variant of Win32/GenKryptik.EELX
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.TIOIBYRW
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.MU
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/GenKryptik.EELX?

Win32/GenKryptik.EELX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment