Malware

Win32/GenKryptik.EZBB malicious file

Malware Removal

The Win32/GenKryptik.EZBB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EZBB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

Related domains:

udre3kvzatwrx6ues4p2u.top

How to determine Win32/GenKryptik.EZBB?


File Info:

crc32: DD5395B5
md5: e835f27f6b6a2b0af42873ce2cc6cc07
name: E835F27F6B6A2B0AF42873CE2CC6CC07.mlw
sha1: 6f0d337dff455f08f29f20a75dd5f2de2d9ae19a
sha256: 84762c5267b583916431e0a1170809b4f366d54fd0d48aea4f07256f10984f84
sha512: c6d079fc59aed72ec45008d48130210a450dc50722ebb3d577ffd7c47f2633a5e11fbea95773a26384bf8ca20da46013731530fbb5c13598b96012cf910ab984
ssdeep: 3072:BCMcU7OCF+6/l8j31YPlV2/1WigHBOGluLO:BOUyCb4F6KUiGvluLO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.EZBB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35851494
Qihoo-360Generic/HEUR/QVM39.1.27B0.Malware.Gen
McAfeeW32/PinkSbot-HE!E835F27F6B6A
MalwarebytesBackdoor.Bot
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.35851494
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D2230CE6
CyrenW32/Trojan.FJQR-2942
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/GenKryptik.33343ed9
RisingTrojan.Generic@ML.93 (RDMK:764B6gWGJqVpYnd3bozfLQ)
Ad-AwareTrojan.GenericKD.35851494
SophosMal/Generic-R + Mal/EncPk-APW
ComodoMalware@#3mcdegzwyldhm
F-SecureTrojan.TR/AD.TriumphLoader.rrsaw
DrWebTrojan.DownLoad4.14218
TrendMicroTROJ_GEN.R031C0PLT20
McAfee-GW-EditionW32/PinkSbot-HE!E835F27F6B6A
FireEyeGeneric.mg.e835f27f6b6a2b0a
EmsisoftTrojan.GenericKD.35851494 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.TriumphLoader.rrsaw
MAXmalware (ai score=100)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Ymacco.AA84
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.35851494
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.34700.oi4@aC3xSfj
ALYacTrojan.GenericKD.35851494
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/GenKryptik.EZBB
TrendMicro-HouseCallTROJ_GEN.R031C0PLT20
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_73%
FortinetW32/GenKryptik.EZBB!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Win32/GenKryptik.EZBB?

Win32/GenKryptik.EZBB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment