Malware

Win32/GenKryptik.EFYS removal tips

Malware Removal

The Win32/GenKryptik.EFYS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EFYS virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.EFYS?


File Info:

crc32: 258B99B6
md5: 1baf4e6f784f35b9cf37d503923067dd
name: vps.exe
sha1: 8dd4dd3bea06fa77f6a5a42a25aeed143ddc0dfa
sha256: 85d030e4f0f92c1f2734f5c644cf5919d2243f5fd8d382c3cf10613dd43f6e8d
sha512: 12ca9f92fdf651b0d126fc9fd96f9b66c6eda1e6192bb2dddb8d5cf4a15b04d906dae07333d156ee9054c6acb7c38218aec876ff2f14344304a04d8a9f2721c9
ssdeep: 12288:0j9fHw7EjUnPjc9brN0w5pVQZ/Ty6xZce3uGeecMbFG36DqQQg:Q9En8rN0w5aLcGsM5Fq
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EFYS also known as:

BkavHW32.Packed.
FireEyeGeneric.mg.1baf4e6f784f35b9
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7GWHacktool ( 700007861 )
BitDefenderThetaGen:NN.ZexaF.34098.NyW@a8UwQ5v
SymantecPacked.Generic.528
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.RanumBot!8.112AC (CLOUD)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.jc
Trapminemalicious.high.ml.score
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/RanumBot.GA!MTB
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ESET-NOD32a variant of Win32/GenKryptik.EFYS
SentinelOneDFI – Suspicious PE
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/GenKryptik.EFYS?

Win32/GenKryptik.EFYS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment