Malware

Win32/GenKryptik.EPLZ malicious file

Malware Removal

The Win32/GenKryptik.EPLZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EPLZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates

Related domains:

help.twitter.com
www.intel.com
support.apple.com
support.oracle.com
ldrpolka.casa

How to determine Win32/GenKryptik.EPLZ?


File Info:

crc32: F1913323
md5: 82a0d2152ae71826dca6103602af2cee
name: upload_file
sha1: 4b0ffd4763df41fcf20ad4c07cba7544e9243f2e
sha256: 0fac76358fcdaffbeb4be0efec66a752a2f900e05ed1d8e861440ab6148b201b
sha512: 82d58fcbd6b6cfe1a8a74987ffb9269802c3d8f4528cd7db72cd401ca706b2c2e3284eea6545b4b4f576416acef4fe57ef47c16b33ac2cbbba09ae6fd2dde547
ssdeep: 3072:ccYZrnyQL8toZWf5phHqhqEd7ckhk1vdag/ahdbNagw4At0wMtU9hCEf8//DBQ8:0Q6Wf5Whv7fMvQbNXtYLMG8
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Offer EnoughClass 1998-2016
CompanyName: Offer EnoughClass
ProductName: Work River bright
ProductVersion: 4.7.8.213
FileDescription: Work River bright
OriginalFilename: same.dll
Translation: 0x0409 0x04e4

Win32/GenKryptik.EPLZ also known as:

MicroWorld-eScanTrojan.GenericKD.43574485
FireEyeTrojan.GenericKD.43574485
McAfeeGenericRXLP-IX!82A0D2152AE7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Cridex.7!c
BitDefenderTrojan.GenericKD.43574485
K7GWTrojan ( 0056bb5b1 )
K7AntiVirusTrojan ( 0056bb5b1 )
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
GDataTrojan.GenericKD.43574485
KasperskyTrojan-Banker.Win32.Cridex.pxa
AlibabaTrojanBanker:Win32/Cridex.6832fb57
NANO-AntivirusTrojan.Win32.Cridex.hpxyjn
TencentWin32.Trojan.Genkryptik.Eadc
Ad-AwareTrojan.GenericKD.43574485
SophosMal/Generic-S
F-SecureTrojan.TR/AD.PhotoDlder.AG
DrWebTrojan.IcedID.30
ZillyaTrojan.Cridex.Win32.989
TrendMicroTROJ_GEN.R002C0WH220
EmsisoftTrojan.GenericKD.43574485 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.SVUI-3674
AviraTR/AD.PhotoDlder.AG
MAXmalware (ai score=80)
Antiy-AVLTrojan[Banker]/Win32.Cridex
MicrosoftTrojan:Win32/Ymacco.AA0F
ArcabitTrojan.Generic.D298E4D5
ZoneAlarmTrojan-Banker.Win32.Cridex.pxa
ALYacTrojan.GenericKD.43574485
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EPLZ
TrendMicro-HouseCallTROJ_GEN.R002C0WH220
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
FortinetW32/ACORult.55FC!tr
BitDefenderThetaGen:NN.ZedlaF.34152.lC8@aW!8Jcei
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.3ab

How to remove Win32/GenKryptik.EPLZ?

Win32/GenKryptik.EPLZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment