Malware

What is “Win32/GenKryptik.GCBB”?

Malware Removal

The Win32/GenKryptik.GCBB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GCBB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Win32/GenKryptik.GCBB?


File Info:

name: 9BF5F8A6DFC0C13D1074.mlw
path: /opt/CAPEv2/storage/binaries/2ce5c56f2c093cb8f5ced5c98075678dce1c17db434f3ce7bc6bfb598e745165
crc32: E692A0A5
md5: 9bf5f8a6dfc0c13d107403247c362ed9
sha1: b9f208d26b6d8498fe0f094c80fd36653bf0da2d
sha256: 2ce5c56f2c093cb8f5ced5c98075678dce1c17db434f3ce7bc6bfb598e745165
sha512: f47228bdc811bb339ac2f3aa7608b51eb54e708dbd32ed5187aaac4b7fec6712e39033c9d746f2223f23983288bcc9fef33afd9416bd09167df332f3280ac769
ssdeep: 98304:aNNoo3gIX60TYIN1UMl5tGDi5elTGwIe03s1UbJ812zC6hpCCJbE1CU:g3g+rBN75g0ecO03vbJRzTpCChG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C43623217F49C3FBC4C3A4359A22E91C7A347E3E5E59B6EFB3C11BCE4A94490E912161
sha3_384: 2c900c432ffac8c5c75ed6d25eb454877f6f089ff716151c999543198cfffe0be4318d21e6b71c48ddc5eaa665701249
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Win32/GenKryptik.GCBB also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.Hulk.Gen.5
CyrenW32/S-e021834d!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GCBB
ClamAVWin.Malware.Fugrafa-9938779-0
MicroWorld-eScanTrojan.Hulk.Gen.5
RisingMalware.SwollenFile!1.DDB4 (CLASSIC)
FireEyeGeneric.mg.9bf5f8a6dfc0c13d
SophosGeneric ML PUA (PUA)
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.Hulk.Gen.5
GoogleDetected
Acronissuspicious
VBA32BScope.TrojanPSW.RedLine
ALYacTrojan.Hulk.Gen.5
APEXMalicious
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/GenKryptik.GCBB?

Win32/GenKryptik.GCBB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment