Malware

Should I remove “Win32/GenKryptik.EVFL”?

Malware Removal

The Win32/GenKryptik.EVFL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EVFL virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

maseratipirosh.top

How to determine Win32/GenKryptik.EVFL?


File Info:

crc32: 19CB4EA9
md5: 473806dd6aef447465fb925629f4afb0
name: upload_file
sha1: eb4280aaddb5f04ef9209e94d279dceff4695ba8
sha256: c0ebb6d2b3647426b5b712c0ab956f8f852edc9dd524082f88b035d009597c2d
sha512: f2ac33ab33c3fe9873768278b06f9cbc7b70ba36a5094cbb3623432c119249af862dfd01fee2cbee28036ea7986c4f0ce19cc606ab78ce145bca803b19c2edd2
ssdeep: 3072:2jXHKpRaF3plqucBu0duHqhaJMas2URZfEMlev+r:2jXHKpQFr1cBV9PZJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Family saw xa9 2016
Mountain: Symbol
InternalName: For LessSpeed
FileVersion: 7.1.2.577
CompanyName: Read farm
ProductName: Interest.dll
ProductVersion: 7.1.2.577
FileDescription: Family saw
Translation: 0x0409 0x04b0

Win32/GenKryptik.EVFL also known as:

McAfeeGenericRXML-CA!473806DD6AEF
CylanceUnsafe
BitDefenderGen:Variant.Johnnie.285617
K7GWTrojan ( 00571fe51 )
K7AntiVirusTrojan ( 00571fe51 )
ArcabitTrojan.Johnnie.D45BB1
SymantecTrojan.Gen.MBT
APEXMalicious
AlibabaTrojan:Win32/IcedID.7648390c
AegisLabTrojan.Win32.Johnnie.4!c
MicroWorld-eScanGen:Variant.Johnnie.285617
RisingTrojan.GenKryptik!8.AA55 (TFE:5:1fVOSjcZ7p)
Ad-AwareGen:Variant.Johnnie.285617
EmsisoftGen:Variant.Johnnie.285617 (B)
TrendMicroTrojan.Win32.ICEDID.THJCOBO
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Johnnie.285617
IkarusTrojan-Banker.IcedID
MicrosoftTrojan:Win32/IcedID.DL!MTB
GDataGen:Variant.Johnnie.285617
ALYacGen:Variant.Johnnie.285617
MAXmalware (ai score=97)
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EVFL
TrendMicro-HouseCallTrojan.Win32.ICEDID.THJCOBO
FortinetW32/GenKryptik.EVFL!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.5cc

How to remove Win32/GenKryptik.EVFL?

Win32/GenKryptik.EVFL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment