Malware

About “Win32/GenKryptik.GBCO” infection

Malware Removal

The Win32/GenKryptik.GBCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GBCO virus can do?

  • Unconventionial language used in binary resources: Arabic (Algeria)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.GBCO?


File Info:

name: 4C0B19D174885BFC35D8.mlw
path: /opt/CAPEv2/storage/binaries/7efa2d8e2755246a0cda857335efa94f4c4cded424c9f38cb02122d79f026a3c
crc32: 507A1509
md5: 4c0b19d174885bfc35d86a3299f386c9
sha1: 353dc6c54b576a654ca4433395e517397e8b1348
sha256: 7efa2d8e2755246a0cda857335efa94f4c4cded424c9f38cb02122d79f026a3c
sha512: 6e531dbfdd267503973375f595a21b05b9e40e2435716400693610ea61541a23029819f67db111aa16368a6b34377e0b44482f360741e1012942025c83685abd
ssdeep: 49152:a/tMwqZFe6iRyhJ3jkqQVSfWVXqASv1x1dKO/5t7WGiocfGJDcjQcy20RHrzKgiR:a/tMwXSjL+EnHOMz5ysZA5+bf6c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13956D05675EBC1A5C85204B509ED97F1093F2A955923886D6FE00E8E0FBF4CB2A6133F
sha3_384: 192b490c1073f62f826008c98050ac5f461dc45c4f59efad47a40a00464ab3c745749299e812abb0bed2ab36705e8a53
ep_bytes: 558bec83c4f0b83c864800e8d4d9f7ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: S te g anos Software GmbH
FileDescription: Steganos Shredder
Translation: 0x0409 0x04e4

Win32/GenKryptik.GBCO also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.62780860
ALYacTrojan.GenericKD.62780860
CylanceUnsafe
VIPRETrojan.GenericKD.62780860
SangforTrojan.Win32.Agent.Vqiy
Cybereasonmalicious.54b576
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GBCO
APEXMalicious
ClamAVWin.Packed.Generickdz-9948392-0
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderTrojan.GenericKD.62780860
TencentWin32.Trojan.Agentb.Bujl
Ad-AwareTrojan.GenericKD.62780860
EmsisoftTrojan.GenericKD.62780860 (B)
DrWebTrojan.DownLoader45.25085
McAfee-GW-EditionBehavesLike.Win32.Worm.th
FireEyeGeneric.mg.4c0b19d174885bfc
GDataTrojan.GenericKD.62780860
GoogleDetected
AviraTR/Kryptik.icmcm
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.813F
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R530013
McAfeeGenericRXUK-SU!4C0B19D17488
MalwarebytesMalware.AI.4281529159
RisingTrojan.Generic@AI.100 (RDML:tK+enqGLLcOOJQtWX/7y1g)
IkarusTrojan.Win32.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FSCS!tr
BitDefenderThetaGen:NN.ZelphiF.34726.@J0@aOWqDSdO
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/GenKryptik.GBCO?

Win32/GenKryptik.GBCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment