Malware

Win32/GenKryptik.EPYL information

Malware Removal

The Win32/GenKryptik.EPYL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EPYL virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.EPYL?


File Info:

crc32: 98E421F6
md5: bf280ccd349b18a67f907f345ffaef37
name: BF280CCD349B18A67F907F345FFAEF37.mlw
sha1: de93fc18b12f5c5834f5a820c100c143de0f018e
sha256: 9be13204445c07beab6889030be5c508ad4b4769966e365d0d81d00131242349
sha512: 7cd024bdf6391b9e752cbbf263010f71a8923f7b8aa68728716de95c5a0c87c89ef8103992a36c675b74732bae3ec4603604e14518e385da67be71504deca20f
ssdeep: 24576:pP3syqAR1jwQQD0oKaJAGfz7gxddqjn5uw9+OFGHrwks:pP8yqA7jwQQ5KaJAm7ptuWGHrwks
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Variant of fucks
FileVersion: 6.36.543
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.14.44
Translation: 0x0273 0x011d

Win32/GenKryptik.EPYL also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056689f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0056689f1 )
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/GenKryptik.EPYL
APEXMalicious
KasperskyVHO:Trojan-Ransom.Win32.Blimp.gen
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fc
FireEyeGeneric.mg.bf280ccd349b18a6
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_76%
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Win-Trojan/MalPe18.Suspicious.X1989
Acronissuspicious
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic@ML.98 (RDML:KIphnx/brN5wVpxjlPufhw)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr

How to remove Win32/GenKryptik.EPYL?

Win32/GenKryptik.EPYL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment