Malware

Win32/GenKryptik.EYPD removal guide

Malware Removal

The Win32/GenKryptik.EYPD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EYPD virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.EYPD?


File Info:

name: 00336A0BA003E93BF8D3.mlw
path: /opt/CAPEv2/storage/binaries/8128dee5768f5f9b2ae43d7eaea71bdd2a901f0c70d9200006943aaa276573c2
crc32: B1843BE2
md5: 00336a0ba003e93bf8d379b990b7f18a
sha1: 620b76d1634806031dc7eab826a0d77b86909354
sha256: 8128dee5768f5f9b2ae43d7eaea71bdd2a901f0c70d9200006943aaa276573c2
sha512: 00648d16e2743dc7f928c05433a66ac9776a595fd85ac675b31185bef800782b639b7861263b1a5c054ed25a33e007ca56a8fca4b882c1dfcb5ce7fbfcb79128
ssdeep: 3072:CKstTBfIMqqDLNQ8LkMxPP2t6e/E74UYa/r+ZFgVEjlNIcAFeNaRr6G1h:CKstTBLqqDLN9vQE/U8SlNIlUe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC25C65272A4C582E8B8063CDCB7BBF40969BC65E9F0891F2574BEDF7C32640492476B
sha3_384: 4fab9b9721dfed9fedd2071915387275b1c8dc7d481c3d450aa10c5b4e5aeab2a8e8968c52516ba77d8d78125519cc1d
ep_bytes: 30303030303030303030303030303030
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/GenKryptik.EYPD also known as:

FireEyeGeneric.mg.00336a0ba003e93b
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 00574c7c1 )
AlibabaTrojan:Win32/GenKryptik.22f7d1d6
K7GWTrojan ( 00574c7c1 )
Cybereasonmalicious.ba003e
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.EYPD
APEXMalicious
AvastWin32:Banker-MYK [Trj]
TencentWin32.Trojan.Falsesign.Bdr
TrendMicroTROJ_FRS.0NA103DL22
McAfee-GW-EditionGenericRXNB-GS!00336A0BA003
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.VB.auee
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.872E75
MicrosoftTrojan:Win32/Ymacco.AA45
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2274457
McAfeeGenericRXNB-GS!00336A0BA003
VBA32Trojan.Wacatac
TrendMicro-HouseCallTROJ_FRS.0NA103DL22
RisingTrojan.Generic@AI.84 (RDML:e640EU2SwtxxUgWgGeTbqQ)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.EZJV!tr
BitDefenderThetaGen:NN.ZexaE.34606.7GX@aOJTUkiI
AVGWin32:Banker-MYK [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/GenKryptik.EYPD?

Win32/GenKryptik.EYPD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment