Malware

Win32/GenKryptik.GCAW removal

Malware Removal

The Win32/GenKryptik.GCAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GCAW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Romanian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.GCAW?


File Info:

name: 4BFE2C36D250BE4FB0FE.mlw
path: /opt/CAPEv2/storage/binaries/25a21079f99ba1fb61380ba117e156b7b861a4bd8cc13d6db01c81c524165d08
crc32: 9F919253
md5: 4bfe2c36d250be4fb0feef1c538bc60f
sha1: 0b2a6b1f2da391f30941af07877a80c57fe36856
sha256: 25a21079f99ba1fb61380ba117e156b7b861a4bd8cc13d6db01c81c524165d08
sha512: f4e370e0226482789cf4fa6be5634756d272bd76c318ef9206d4e3c602921260c2a4098a06f135b6751175a4db05a019db717f775fd1519b64a438606a087c18
ssdeep: 98304:Na+E4gVzefIJOqBrTAtJO9rQ++b8rYAEx6b7w4wT/wG1VNUl:c+JMz1JrrEnOS/hrx6b7wxwGds
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101163320364185F3EDB211F56942CF5C5375F67698BA88AB7B840A7E2FF02C136785CA
sha3_384: 347f6f99dcc21244b19b800c6c21ee6fbf5c7a5ef0d53a4350f283b3e8701141cbc4e6f3bd45814383d924f7587c460c
ep_bytes: e8db740000e979feffff8b4c2404f7c1
timestamp: 2021-06-17 12:04:40

Version Info:

Translations: 0x0541 0x007e

Win32/GenKryptik.GCAW also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.Siggen19.4951
MicroWorld-eScanGen:Heur.Mint.Zard.52
ALYacGen:Heur.Mint.Zard.52
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.HZA.gen!Eldorado
SymantecPacked.Generic.528
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GCAW
APEXMalicious
KasperskyVHO:Trojan-Spy.Win32.Windigo.gen
BitDefenderGen:Heur.Mint.Zard.52
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Heur.Mint.Zard.52
EmsisoftGen:Heur.Mint.Zard.52 (B)
VIPREGen:Heur.Mint.Zard.52
McAfee-GW-EditionPacked-GEE!4BFE2C36D250
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4bfe2c36d250be4f
SophosML/PE-A + Troj/Krypt-QV
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Mint.Zard.52
GoogleDetected
ArcabitTrojan.Mint.Zard.52
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@AI.90 (RDML:PRj1Lux49jt5IQiOO4JXPg)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.GBZR!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Win32/GenKryptik.GCAW?

Win32/GenKryptik.GCAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment