Malware

About “Win32/GenKryptik.EZHW” infection

Malware Removal

The Win32/GenKryptik.EZHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EZHW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

gxd3fp7fe7cac6jzn2sac.online

How to determine Win32/GenKryptik.EZHW?


File Info:

crc32: 8FEEE98B
md5: 7b096d2eff222ffdca172c7d84866e0a
name: 7B096D2EFF222FFDCA172C7D84866E0A.mlw
sha1: 1f0c72c74fedcf834e0a5abb0f1466131d1c21c1
sha256: 8b3f0c5cc71813d2410bbb5f13a901188076a6651c0858e7ba96ead3e0b1c164
sha512: 5227e295aad2b0003cf4e7828c0bd90d971448a872a028008373d53a49360c29904cdac648ecc157e43b2dad63bd3c43bad0b3a0a1f59121c43c4d6c8f744912
ssdeep: 12288:cl0Xud8yOVLynaBqqz634uRDi4FPRqkl6:ruWyDawqsD1Vs
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.5
TranslationUsa: 0x0273 0x04d3

Win32/GenKryptik.EZHW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45257120
FireEyeGeneric.mg.7b096d2eff222ffd
ALYacTrojan.GenericKD.45257120
MalwarebytesTrojan.MalPack.GS
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKD.45257120
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34742.CmKfa8hGfpmG
CyrenW32/Trojan.YCEA-5051
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.blcn
AlibabaTrojanSpy:Win32/SpyEyes.44ed0d6b
ViRobotTrojan.Win32.Z.Peerfrag.462848
AegisLabTrojan.Win32.SpyEyes.l!c
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.45257120
ComodoMalware@#2n9whoj3h9qah
DrWebTrojan.DownLoader36.31791
TrendMicroTROJ_GEN.R002C0DA321
McAfee-GW-EditionBehavesLike.Win32.Trojan.gc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/AD.TriumphLoader.bfsbw
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Troj.SpyEyes.bl.(kcloud)
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B291A0
ZoneAlarmTrojan-Spy.Win32.SpyEyes.blcn
GDataTrojan.GenericKD.45257120
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361497
McAfeeRDN/TriumphLoader
VBA32BScope.Trojan.Glupteba
ESET-NOD32a variant of Win32/GenKryptik.EZHW
TrendMicro-HouseCallTROJ_GEN.R002C0DA321
IkarusWorm.Win32.Peerfrag
FortinetW32/Kryptik.HIFA!tr
WebrootW32.Trojan.Glupteba
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.74fedc
PandaTrj/GdSda.A
Qihoo-360Generic/HEUR/QVM11.1.481B.Malware.Gen

How to remove Win32/GenKryptik.EZHW?

Win32/GenKryptik.EZHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment