Malware

Win32/GenKryptik.EVEV information

Malware Removal

The Win32/GenKryptik.EVEV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EVEV virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:27783
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Attempts to execute a powershell command with suspicious parameter/s
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.EVEV?


File Info:

crc32: 39B172B5
md5: 21008ea964855e40a4e883b1ce96362e
name: asura.exe
sha1: 8ce40f5f43f8764dd4b7e669e3c35a425989a18a
sha256: e92e3f33e873e72ed20eaf98a5b13c1a21164db9793242e3d727ae9f6cad0b4c
sha512: 9ca9ee18fb7b8e58c2149153d3c40019c7dbd1156d315a49793dae14e2473fee898d51f15f7f394a6ed0a761d878e70584e7f0142ee9052b342f7bc1952a6a40
ssdeep: 98304:B2OMhSXVbiNEAhGYsCUWCGYEQemK1KZsa7SM6zX1nyX0vvD7Z29O/txyCHoscr:B2nhCQiAhLOEQDZsOSM6z9yWD7Ic1cCc
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

InternalName: wriheovbz.ote
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, pumke
TranslationUsi: 0x0431 0x0cca

Win32/GenKryptik.EVEV also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.21008ea964855e40
McAfeeArtemis!21008EA96485
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Generic@ML.100 (RDML:cabNRGEYF1wRDbE8eklEtQ)
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SentinelOneDFI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.DE!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.@t1@aCu2oqoe
ESET-NOD32a variant of Win32/GenKryptik.EVEV
eGambitUnsafe.AI_Score_99%
AVGFileRepMalware
Cybereasonmalicious.f43f87
Qihoo-360HEUR/QVM10.1.E030.Malware.Gen

How to remove Win32/GenKryptik.EVEV?

Win32/GenKryptik.EVEV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment