Malware

Win32/GenKryptik.EGBT information

Malware Removal

The Win32/GenKryptik.EGBT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EGBT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

marroiq.com

How to determine Win32/GenKryptik.EGBT?


File Info:

crc32: 751EA783
md5: e06cdf38d58d0c5e9c048b0e23d4a726
name: billiz.exe
sha1: 898161095e3765b525e809057de0ac0bcb2f3776
sha256: 77eae0bb623714f3bbb31f54f03f8e5022c4450e8ef50c28ae682d9565d2f682
sha512: 59b0cbf203bd5099a3e6bcd79cefdbd214b4b97bf29cf7d1491d2477ba38e95ef96747ae63a70fc26720b8f81ef6652208ddadac27ae84c7ddbf70ef2d79f1a9
ssdeep: 12288:8xe/Q1nfvxSmigDbgUO+h+/rYE3BSybrsxaFKzudQ+b7GgQaqxD/SnKQ8rQvb4sH:Qe4Sxw/i3g4osFLDkaqVSnkQvcE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EGBT also known as:

FireEyeGeneric.mg.e06cdf38d58d0c5e
CylanceUnsafe
SangforMalware
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.95e376
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazqiPGMhsV8wy5EeyZkegrrA)
Endgamemalicious (high confidence)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
Trapminemalicious.moderate.ml.score
SophosMal/Fareit-V
MaxSecureTrojan.Malware.300983.susgen
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Pwsteal.Q!bit
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ESET-NOD32a variant of Win32/GenKryptik.EGBT
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.EESQ!tr
BitDefenderThetaGen:NN.ZelphiF.34100.1GW@aWiBMYoi
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM05.1.D24B.Malware.Gen

How to remove Win32/GenKryptik.EGBT?

Win32/GenKryptik.EGBT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment