Malware

About “Win32/GenKryptik.EQKR” infection

Malware Removal

The Win32/GenKryptik.EQKR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EQKR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
help.twitter.com
www.intel.com
coverbeacon.top
support.oracle.com
support.apple.com

How to determine Win32/GenKryptik.EQKR?


File Info:

crc32: 7D0D1D79
md5: f760cde08c84eadf4e104457ca0713af
name: upload_file
sha1: 259754e272ab5fcb70a999b6ca44ccf9b7c9eea1
sha256: 8d0b6f6b36e7a5ab3b79ee7c922b55e868cba16e8980eb50caea8dcadb842e61
sha512: 017af7c0485fb77db2fd9e18f8e69fe1d7fe04ab5bd52f5af88ae922d59dc3a7d3da20a17be449df8d2343c8a8152471337b719664f56525067cc15a7cc042e7
ssdeep: 3072:qMGgQntajGy1ukP3tOWk+Xo4jUGZJ8dIqJxw6DiPdlKWWg:qLIjf1vP3tS+VjjZJ5q4gclr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EQKR also known as:

MicroWorld-eScanTrojan.GenericKDZ.69471
FireEyeGeneric.mg.f760cde08c84eadf
McAfeeGenericRXLR-RW!F760CDE08C84
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 0056c8601 )
BitDefenderTrojan.GenericKDZ.69471
K7GWTrojan ( 0056c9531 )
TrendMicroTROJ_GEN.R011C0DHH20
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
AlibabaTrojan:Win32/IcedId.4dd9262e
ViRobotTrojan.Win32.Z.Genkryptik.199680.AP
RisingTrojan.Kryptik!1.CAAD (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69471
F-SecureTrojan.TR/AD.PhotoDlder.haljq
DrWebTrojan.IcedID.30
FortinetW32/GenKryptik.EQKR!tr
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Valak
AviraTR/AD.PhotoDlder.haljq
MAXmalware (ai score=84)
ArcabitTrojan.Generic.D10F5F
MicrosoftTrojan:Win32/IcedId.DBM!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.R347925
ALYacTrojan.GenericKDZ.69471
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQKR
TrendMicro-HouseCallTROJ_GEN.R011C0DHH20
TencentWin32.Trojan.Generic.Eddg
eGambitUnsafe.AI_Score_95%
GDataTrojan.GenericKDZ.69471
BitDefenderThetaGen:NN.ZedlaF.34152.mu4@aqs!z8li
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.39b

How to remove Win32/GenKryptik.EQKR?

Win32/GenKryptik.EQKR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment