Malware

What is “Win32/GenKryptik.EVHE”?

Malware Removal

The Win32/GenKryptik.EVHE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EVHE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.intel.com
support.oracle.com
help.twitter.com
redicilious.online
support.apple.com

How to determine Win32/GenKryptik.EVHE?


File Info:

crc32: 704147B0
md5: cf4e1c9891868af88b81a6f834149103
name: upload_file
sha1: b3dcc1f80280d0ef67ed50a10889afbb74209455
sha256: b2c289be94c22e37b2835a7f532cc3995459892fa7fe865175f69b1bc0e1a20b
sha512: ed19717b5617b6b121ed1bb0fcf64bd356a92bdb71e96e070756bf6d1bb5bb3d4da5e43ccfb0dbfcfded97784cfbcc631361d2339d646ed6d6c338305392eaaa
ssdeep: 6144:l3zDUbuCM/zV1boMSThnjCEt+Ay15GaC14qQQd/ZzRzYNjNo/+qnAB:l3iubgM61jt+AyiaCdVdRtzYNjNo/+I0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Science mount xa9 2014
Division: Bat
InternalName: Change ThereTurn
FileVersion: 3.7.6.186
CompanyName: Symbol egg
ProductName: copy.dll
ProductVersion: 3.7.6.186
FileDescription: Science mount
Translation: 0x0409 0x04b0

Win32/GenKryptik.EVHE also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.44259970
FireEyeTrojan.GenericKD.44259970
McAfeeGenericRXAA-AA!CF4E1C989186
CylanceUnsafe
AegisLabTrojan.Win32.IcedID.7!c
BitDefenderTrojan.GenericKD.44259970
K7GWTrojan ( 00571fbe1 )
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.IcedID.gen
AlibabaTrojanBanker:Win32/GenKryptik.18552818
Ad-AwareTrojan.GenericKD.44259970
F-SecureTrojan.TR/Kryptik.lesea
DrWebTrojan.IcedID.30
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44259970 (B)
SentinelOneDFI – Suspicious PE
AviraTR/Kryptik.lesea
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmHEUR:Trojan-Banker.Win32.IcedID.gen
GDataWin32.Trojan.Agent.V0RCA0
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZedlaF.34590.vu9@aa0rf0ei
ESET-NOD32a variant of Win32/GenKryptik.EVHE
RisingTrojan.Generic@ML.84 (RDML:e2UJZSVa3L9fOR31Ndsn7g)
IkarusWin32.Outbreak
FortinetW32/GenKryptik.EVFL!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.0f5

How to remove Win32/GenKryptik.EVHE?

Win32/GenKryptik.EVHE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment