Malware

Win32/GenKryptik.EUVB malicious file

Malware Removal

The Win32/GenKryptik.EUVB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EUVB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.EUVB?


File Info:

crc32: AE63FDDF
md5: bb997b6a52b627851e9bf3bb93104f0a
name: eaqWDLBCrZpMTOAo.exe
sha1: bdaa4cadcff1a44f995fd40e52e50be2f561c2b2
sha256: 829f75211280d0ac2ed4a59b137c942c909416e5f5a3839f2f2ea8bb3c61bade
sha512: 761a7022b2abdace78d093aa406bbfcef4c82eae21628795c2ee8560f1d54679186b15f1e9194e99d3fe09abbfba26431f867943a23e5e5a937da4c2614330d4
ssdeep: 12288:PvqNP1ohDKr5qL25eP+hKAlGqGkdJRSx:kucr5qKaYKyGqRnSx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2008 Hans Dietrich
FileVersion: 1, 0, 0, 1
ProductName: XGradientZoneBarTest Application
E-mail: hdietrich@gmail.com
ProductVersion: 1, 0, 0, 1
FileDescription: XGradientZoneBarTest MFC Application
Article: www.codeproject.com
OriginalFilename: XGradientZoneBarTest.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.EUVB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.bb997b6a52b62785
McAfeeEmotet-FSF!BB997B6A52B6
CylanceUnsafe
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
DrWebTrojan.DownLoader35.5305
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
MicrosoftTrojan:Win32/EmotetCrypt!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.Agent.EXYO
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34570.Eu0@aOnAJyni
MAXmalware (ai score=89)
ESET-NOD32a variant of Win32/GenKryptik.EUVB
RisingTrojan.Generic@ML.100 (RDML:4cvWFM5U17EcEAo8Ikbtag)
SentinelOneDFI – Suspicious PE
FortinetW32/Emotet.CI!tr
WebrootW32.Trojan.Emotet
Qihoo-360HEUR/QVM10.1.C01B.Malware.Gen

How to remove Win32/GenKryptik.EUVB?

Win32/GenKryptik.EUVB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment