Malware

What is “Win32/GenKryptik.EUNW”?

Malware Removal

The Win32/GenKryptik.EUNW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EUNW virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

whatismyipaddress.com

How to determine Win32/GenKryptik.EUNW?


File Info:

crc32: B4C2C6F4
md5: b630aff90115076ae13226892d4473ce
name: order19102020.exe
sha1: df071853379921d280ebe7cdcd9fa87bea680f41
sha256: 9e45f4bd47d0e7aa3bbf2d17de85b2beeb7ce6f846b8c607537ffe0cd41bd3d3
sha512: b8217dbce976548fba45c4108bfe60ad062cc83b9e60f44b63e732d51a07f2eaa4bac7e943f90606ed511350b699284632680f27d31518067977d0dad79fc32d
ssdeep: 24576:/5XY4uAU6mvtzG0+NyvrGDVqitvN0teM53u8iD81:xvVUL9vr4lt10ne8ii
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Cao;1[786orp.
InternalName:
FileVersion: 554666
CompanyName: lhnyu Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 711-
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/GenKryptik.EUNW also known as:

Elasticmalicious (high confidence)
McAfeePWS-FCRZ!B630AFF90115
SangforMalware
BitDefenderGen:Variant.Graftor.836296
Cybereasonmalicious.337992
ArcabitTrojan.Graftor.DCC2C8
InvinceaML/PE-A
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
MicroWorld-eScanGen:Variant.Graftor.836296
RisingTrojan.Generic@ML.99 (RDML:vat4KslLSjzRFITjmXdqIg)
Ad-AwareGen:Variant.Graftor.836296
EmsisoftGen:Variant.Graftor.836296 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.b630aff90115076a
JiangminTrojanDownloader.Agent.fgpr
MicrosoftTrojan:Win32/Wacatac.D9!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Graftor.836296
Acronissuspicious
ALYacGen:Variant.Graftor.836296
MAXmalware (ai score=87)
VBA32BScope.Trojan.Scarsi
ESET-NOD32a variant of Win32/GenKryptik.EUNW
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZelphiF.34570.cH0@aqmBmcii
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/GenKryptik.EUNW?

Win32/GenKryptik.EUNW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment