Malware

How to remove “Win32/GenKryptik.EQDC”?

Malware Removal

The Win32/GenKryptik.EQDC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EQDC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

www.intel.com
support.apple.com
nothingtodo.co

How to determine Win32/GenKryptik.EQDC?


File Info:

crc32: 2F390136
md5: e43f6af2d55147cbf4c2942d0371e103
name: upload_file
sha1: ea3e3cb78571604c1a6a3852695d4369fac6b04c
sha256: cae030f43d77e7bdad04d3e6d85f3dafc28b9a33186de46ad93074317a8c2bae
sha512: 41672caaebcfa79cf6bba2ff86017f2164fe75f300da2dda7521bb1e92f48ef447b446d61b5437101c4bee9fbb3588f36187103ab768013e310632ef3cf94f6b
ssdeep: 3072:GQYETBgAE8/hID93UoTLKringNHosBx+p+m6jbN:kEAOoTLKrinqIsBxk6p
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Syllable Mass their xa9 2013
InternalName: Before minute Cloud big
FileVersion: 3.7.0.898
CompanyName: Help RunList
ProductName: Side.dll
ProductVersion: 3.7.0.898
FileDescription: Syllable Mass their
Translation: 0x0409 0x04b0

Win32/GenKryptik.EQDC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34340472
BitDefenderTrojan.GenericKD.34340472
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.IcedID.twpw
RisingTrojan.GenKryptik!8.AA55 (C64:YzY0Ov+qQbBgpJ4H)
Ad-AwareTrojan.GenericKD.34340472
Comodo.UnclassifiedMalware@0
FireEyeGeneric.mg.e43f6af2d55147cb
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/IcedId.DA!MTB
ArcabitTrojan.Generic.D20BFE78
ZoneAlarmTrojan-Banker.Win32.IcedID.twpw
GDataTrojan.GenericKD.34340472
VBA32BScope.TrojanSpy.Zbot
ESET-NOD32a variant of Win32/GenKryptik.EQDC
IkarusTrojan-Banker.IcedID
FortinetW32/IcedID.EQDC!tr
BitDefenderThetaGen:NN.ZedlaF.34152.ju8@aS4DRjci
AVGFileRepMalware

How to remove Win32/GenKryptik.EQDC?

Win32/GenKryptik.EQDC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment