Malware

Should I remove “Win32/GenKryptik.EQKN”?

Malware Removal

The Win32/GenKryptik.EQKN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EQKN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

help.twitter.com
www.intel.com
coverbeacon.top
support.oracle.com
support.apple.com

How to determine Win32/GenKryptik.EQKN?


File Info:

crc32: D5C38910
md5: ee525ccbae24825d5138dc053bc5cb2c
name: upload_file
sha1: f9bfa18a7e6d1e408185871cb5ce71cb60b3d9be
sha256: 0d778b003ebf1f618b9a631e306c2aec2cdeac096bda2a9de5746a172deb057e
sha512: 1abb74bbda6273b68643447302554b80976f6cba05e53e75d43f2a59320261a6d6be3d519e1840f2514e1e8a86b7454570509627639942e5035c5e9996f1f5ac
ssdeep: 3072:7xGsdbiJzU6dIXqsYDkRmLmSmMePbuL5WbA6Id1HUhL:IsdbGhd+qsYRice9/Jh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EQKN also known as:

MicroWorld-eScanTrojan.GenericKD.43665106
FireEyeTrojan.GenericKD.43665106
Qihoo-360Win32/Trojan.b65
BitDefenderTrojan.GenericKD.43665106
KasperskyTrojan-Banker.Win32.IcedID.twqd
Ad-AwareTrojan.GenericKD.43665106
F-SecureTrojan.TR/AD.PhotoDlder.AY
DrWebTrojan.IcedID.30
AviraTR/AD.PhotoDlder.AY
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.C!ml
BitDefenderThetaGen:NN.ZedlaF.34152.mu4@a46xF!ii
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQKN
GDataWin32.Trojan.Agent.1V7WO2

How to remove Win32/GenKryptik.EQKN?

Win32/GenKryptik.EQKN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment