Malware

Win32/GenKryptik.ESLP removal

Malware Removal

The Win32/GenKryptik.ESLP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.ESLP virus can do?

  • At least one process apparently crashed during execution
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.ESLP?


File Info:

name: D61099FFF295B65FF624.mlw
path: /opt/CAPEv2/storage/binaries/3fdac0142a7176070a8478527119be2d62d024966a7cfaabac7aa2619fdbb98a
crc32: AA071644
md5: d61099fff295b65ff6247e19852df843
sha1: 469ee3304b9720cc2677fa71e4b53cf1dbf267f7
sha256: 3fdac0142a7176070a8478527119be2d62d024966a7cfaabac7aa2619fdbb98a
sha512: e5c03fc84c25798dc35ad274439210ac764417054be2bac4ac69d1d5c67ddd1d991ca85150ec13bdd1f92139ed307437d08c239dcd19bf59e53326e290b25a42
ssdeep: 6144:oGOTQ00jLDdp6nN3mP4qQnJSqYDzPieoAOyEyrxXMx+m2wtFrx:xOTSLDSO4qyJSqEW/sEyrmx++tFr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D548D0275E2C0B2E5B609324DB8AAA259FD79650832CE7F23E44A1EDF315C1D635B73
sha3_384: 374e889a009f1e44a7b160d8c95287b0ab02cf03346577d68a9ba1228e60c8095cde5316b26791af6c74eaf122ef087c
ep_bytes: e867050000e97afeffff558bec6a00ff
timestamp: 2019-12-02 23:33:39

Version Info:

CompanyName: Google LLC
FileDescription: Google Crash Handler
FileVersion: 1.3.35.421
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: GoogleUpdate.exe
ProductName: Google Update
ProductVersion: 1.3.35.421
Translation: 0x0409 0x04b0

Win32/GenKryptik.ESLP also known as:

LionicTrojan.Win32.Babar.4!c
MicroWorld-eScanGen:Variant.Babar.22494
FireEyeGen:Variant.Babar.22494
McAfeeArtemis!D61099FFF295
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.111695
K7AntiVirusTrojan ( 0056ea8e1 )
AlibabaTrojan:Win32/GenKryptik.dcdeb74c
K7GWTrojan ( 0056ea8e1 )
Cybereasonmalicious.ff295b
ArcabitTrojan.Babar.D57DE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.ESLP
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
BitDefenderGen:Variant.Babar.22494
TencentWin32.Trojan.Babar.Woyy
Ad-AwareGen:Variant.Babar.22494
EmsisoftGen:Variant.Babar.22494 (B)
AviraHEUR/AGEN.1136373
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Babar.22494
ALYacGen:Variant.Babar.22494
MAXmalware (ai score=80)
APEXMalicious
RisingTrojan.Generic@ML.84 (RDML:KROycHcrOVsPHdgfS9X49g)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.3E08!tr
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/GenKryptik.ESLP?

Win32/GenKryptik.ESLP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment