Malware

About “Win32/GenKryptik.ESRI” infection

Malware Removal

The Win32/GenKryptik.ESRI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.ESRI virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.ESRI?


File Info:

crc32: 55E75D22
md5: d213c25eb7528fbc07f48fb9c151f0ed
name: D213C25EB7528FBC07F48FB9C151F0ED.mlw
sha1: 31238a41bd1c75344191476d2e9d0cdbbe209ad7
sha256: ababc29fccbf34ef3fbd7646a9f20635b97f749f849be02bd16d86e087be86a5
sha512: 0a3173bca5fff2c330434ea2f95815c1291ea71e4fec9c2a27cda1839d311c4148e751578a19e8d611e9d8577155b13c5d70e8981e84831550db294ed4a96d5d
ssdeep: 6144:YN2FKp7Q/Ks3FyQhQRrHoFN6WtljaJul+pw8T:s2kp7YFalHoFN6WtljaElI9T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: MyPad
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MyPad Application
ProductVersion: 1, 0, 0, 1
FileDescription: MyPad MFC Application
OriginalFilename: MyPad.EXE
Translation: 0x0409 0x04b0

Win32/GenKryptik.ESRI also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057b02c1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader38.37318
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Rincux2
ALYacDeepScan:Generic.Rincux2.7BEE49EF
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.84484
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Farfli.0232da9f
K7GWTrojan ( 0057b02c1 )
Cybereasonmalicious.eb7528
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.ESRI
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Farfli-9790741-0
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderDeepScan:Generic.Rincux2.7BEE49EF
NANO-AntivirusTrojan.Win32.Farfli.iuhdwg
ViRobotTrojan.Win32.Z.Farfli.647168.B
MicroWorld-eScanDeepScan:Generic.Rincux2.7BEE49EF
Ad-AwareDeepScan:Generic.Rincux2.7BEE49EF
SophosMal/Generic-S
ComodoTrojWare.Win32.Magania.A@5wdy5u
BitDefenderThetaGen:NN.ZexaF.34690.Nq0@ae5qMJii
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d213c25eb7528fbc
EmsisoftDeepScan:Generic.Rincux2.7BEE49EF (B)
JiangminBackdoor.Farfli.eua
AviraHEUR/AGEN.1142366
MicrosoftTrojan:Win32/Farfli.DSK!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s1
AegisLabTrojan.Win32.DeepScan.4!c
GDataDeepScan:Generic.Rincux2.7BEE49EF
AhnLab-V3Backdoor/Win.ZEGOST.C4430098
McAfeeGenericRXAA-AA!D213C25EB752
MAXmalware (ai score=84)
VBA32Backdoor.Lotok
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
RisingTrojan.Kryptik!1.D241 (CLOUD)
YandexTrojan.GenKryptik!atMgb7KRYiw
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.73947863.susgen
FortinetW32/GenKryptik.EOZH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.ESRI?

Win32/GenKryptik.ESRI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment