Malware

Win32/GenKryptik.EFZE removal tips

Malware Removal

The Win32/GenKryptik.EFZE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EFZE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking

How to determine Win32/GenKryptik.EFZE?


File Info:

crc32: 84DEFD9C
md5: d150af36f2f3491f0c5f494a955cbd3a
name: 2.exe
sha1: 985e5116c2236240339502e3473e5dc7a1345b30
sha256: adb4772d8d5f9ede7d8b52b1beb66db50b616e97d30231290240dbd9cda75b3e
sha512: 33e14c7fd573853341eaaa5c222e441c21d21ad925d031ed7dd1db7fa25eb30af5995797c3f016dee28f99b15adb84c542cb0e7485be7d17a51afc65694bd101
ssdeep: 49152:if9Q234inibHWwqq8tRcFcQXoXxxqO9zt1f5f0O:q9Q234bbe1yO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Alaborn Apps, Inc. Copyright xa9 2016 All rights reserved.
FileVersion: 7.4.4.8
CompanyName: Alaborn Apps, Inc.
FileDescription: Cnverters Paper Implementation 176 Authenticode
ProductName: Readystate
ProductVersion: 7.4.4.8
PrivateBuild: 7.4.4.8
OriginalFilename: Readystate.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.EFZE also known as:

MicroWorld-eScanTrojan.GenericKD.33532821
McAfeeArtemis!D150AF36F2F3
CylanceUnsafe
K7AntiVirusTrojan ( 005622901 )
BitDefenderTrojan.GenericKD.33532821
K7GWTrojan ( 005622901 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33532821
KasperskyTrojan-PSW.Win32.Racealer.dtx
AlibabaTrojanPSW:Win32/Racealer.04097bd0
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan-qqpass.Qqrob.Wopc
SophosMal/Generic-S
F-SecureTrojan.TR/AD.StellarStealer.svfgo
DrWebTrojan.PWS.Siggen2.44669
TrendMicroPossible_HPGen-38
McAfee-GW-EditionBehavesLike.Win32.Ursnif.vh
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33532821 (B)
AviraTR/AD.StellarStealer.svfgo
Antiy-AVLTrojan[PSW]/Win32.Racealer
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FFAB95
ZoneAlarmTrojan-PSW.Win32.Racealer.dtx
VBA32BScope.Trojan.Casur
ALYacTrojan.GenericKD.33532821
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.33532821
MalwarebytesSpyware.RaccoonStealer
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.EFZE
TrendMicro-HouseCallPossible_HPGen-38
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan-Ransom.Crypter
FortinetW32/Racealer.DTX!tr.pws
BitDefenderThetaGen:NN.ZexaF.34100.as0@aiegYlpi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.d2a

How to remove Win32/GenKryptik.EFZE?

Win32/GenKryptik.EFZE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment