Malware

Win32/GenKryptik.EQLA removal guide

Malware Removal

The Win32/GenKryptik.EQLA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EQLA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

jamalrnukkam58.sytes.net

How to determine Win32/GenKryptik.EQLA?


File Info:

crc32: 992C6EE5
md5: aca62962ec59c2317cabbb1422245514
name: upload_file
sha1: a03c91a79057d8acfdbb1debd234ebf77aa97bff
sha256: 28d8e7c63a11bda1623e1a9a660972e234199771d4b84d44e1143bee1aa1e86b
sha512: 910fde9a0bd95d48b61afd73fde2039f908fa82a49aca09c484e4c52aa5d30d9c8ec3fa4efde8d7450ffb4ae9f9aef01a5d9eb34e5aaff15f0e18d5fe663d78a
ssdeep: 12288:TzrtkYBjJ/JoxxB7FyKGXepX48419bpArIilO7XE7aOoQwuBmYe21A9BSKS:TP2qJ/JonTx5t6KI7X1f8vCrSL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EQLA also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34363882
McAfeeArtemis!ACA62962EC59
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
BitDefenderTrojan.GenericKD.34363882
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/Delf.AHD
SymantecInfostealer.Lokibot!43
ESET-NOD32a variant of Win32/GenKryptik.EQLA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
RisingTrojan.NanoCore!8.527 (CLOUD)
Ad-AwareTrojan.GenericKD.34363882
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Kryptik.yeexs
TrendMicroTROJ_FRS.0NA104HF20
MaxSecureTrojan.Malware.300983.susgen
FireEyeGeneric.mg.aca62962ec59c231
SophosMal/Generic-S
IkarusTrojan.Inject
CyrenW32/Delf.IWTO-6731
AviraTR/Kryptik.yeexs
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/NanoCore.VD!MTB
ArcabitTrojan.Generic.D20C59EA
GDataTrojan.GenericKD.34363882
CynetMalicious (score: 100)
AhnLab-V3Suspicious/Win.Delphiless.X2091
Acronissuspicious
ALYacTrojan.GenericKD.34363882
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA104HF20
TencentWin32.Trojan.Kryptik.Lpva
SentinelOneDFI – Suspicious PE
FortinetW32/Injector.EMZL!tr
BitDefenderThetaGen:NN.ZelphiF.34152.XGW@a0p!Gibi
AVGWin32:Malware-gen
Cybereasonmalicious.79057d
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM05.1.47CD.Malware.Gen

How to remove Win32/GenKryptik.EQLA?

Win32/GenKryptik.EQLA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment