Malware

Win32/GenKryptik.EVEK (file analysis)

Malware Removal

The Win32/GenKryptik.EVEK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EVEK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

www.intel.com
support.apple.com
support.oracle.com
help.twitter.com
zomboboxer.top

How to determine Win32/GenKryptik.EVEK?


File Info:

crc32: 692C5606
md5: 0f968175529219cad64d8719010faadd
name: upload_file
sha1: 063f7556bf9bc0ffd6aa4a637c95521665f17d05
sha256: a683de41288a3655a95ffd5e61743211077eff9acebbf129e7614a064b9bfbf4
sha512: c02ac4f33f2e22955ca24aff6104daec1a5fe37251fd7d60081510018f7e4732cf213225b81eae01c3e9151742be5476dd4eca44730e2341fcbd6bfd6413de78
ssdeep: 3072:Su6Nt36EfNKj0li470vwt3nVr3DTFlxg9V2uFQ/iKE9LHOCEppy+:+Nx6Hj0cpvwt3VjDtgT2gQKKc1Epp
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Perhaps gentle xa9 2011
InternalName: Separate AllCan
FileVersion: 4.3.1.639
CompanyName: Shell wrong
Fat: Road
ProductName: brought.dll
ProductVersion: 4.3.1.639
FileDescription: Perhaps gentle
Translation: 0x0409 0x04b0

Win32/GenKryptik.EVEK also known as:

MicroWorld-eScanGen:Variant.Zusy.325992
FireEyeGen:Variant.Zusy.325992
McAfeeGenericRXAA-AA!0F9681755292
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/IcedID.60e9aa9e
K7GWTrojan ( 00571e401 )
K7AntiVirusTrojan ( 00571e401 )
InvinceaMal/Generic-S
SymantecTrojan.Gen.MBT
BitDefenderGen:Variant.Zusy.325992
Paloaltogeneric.ml
AegisLabTrojan.Win32.Midie.4!c
Ad-AwareGen:Variant.Zusy.325992
ComodoTrojWare.Win32.Agent.ugbvr@0
F-SecureTrojan.TR/Kryptik.xyzrc
DrWebTrojan.IcedID.30
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Zusy.325992 (B)
WebrootW32.Trojan.Icedid
AviraTR/Kryptik.xyzrc
MicrosoftTrojan:Win32/IcedID.DL!MTB
ArcabitTrojan.Zusy.D4F968
GDataGen:Variant.Zusy.325992
CynetMalicious (score: 85)
ALYacGen:Variant.Zusy.325992
MAXmalware (ai score=85)
MalwarebytesTrojan.IcedID
ESET-NOD32a variant of Win32/GenKryptik.EVEK
TrendMicro-HouseCallTROJ_GEN.R002H0CJT20
RisingMalware.Undefined!8.C (TFE:5:b7SvN75ZNYB)
IkarusTrojan-Banker.IcedID
FortinetW32/GenKryptik.EVEK!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
Qihoo-360Generic/Trojan.be2

How to remove Win32/GenKryptik.EVEK?

Win32/GenKryptik.EVEK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment