Malware

Win32/GenKryptik.GEVR (file analysis)

Malware Removal

The Win32/GenKryptik.GEVR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GEVR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenKryptik.GEVR?


File Info:

name: A59C9843D3A223F59848.mlw
path: /opt/CAPEv2/storage/binaries/428f5f676a7d102074feeb45c5e2b8c500a8a80bde56b3815b67e889fad0d17a
crc32: 21856E7F
md5: a59c9843d3a223f59848484ce340a648
sha1: 37d80cf3c1b28ed94c831fbe02cd7efda9abf02a
sha256: 428f5f676a7d102074feeb45c5e2b8c500a8a80bde56b3815b67e889fad0d17a
sha512: 0afc42f47c3434a68fcefe198210f1722de03ef98f135647b2c75d6886eae67388a50a47ead15b16d13b538a525355deac5502370a4a64167b56bb86255d9788
ssdeep: 98304:H+YSuxtNWhYozcRKxY329zFiYW7b6CRy:HjNokKxK8FEs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8F5335837B9F6D3C99A6B7642F18A0A43F6FF0A1F64CBEE7651293F1B2E0209D14540
sha3_384: 3c346f49b4567b007cf4a47496b270577a687c65555a9c1216387950464ef997bcfd7eb211b371e2187b19468a203755
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2054-09-07 22:21:43

Version Info:

Translation: 0x0000 0x04b0
Comments: CEnoiiKickName
CompanyName: SAIPRO X-NETWORK
FileDescription: CEnoiiKickName
FileVersion: 2.9
InternalName: CEnoiiKickName.exe
LegalCopyright: MintSaipro © 2021
LegalTrademarks:
OriginalFilename: CEnoiiKickName.exe
ProductName: CEnoiiKickName
ProductVersion: 2.9
Assembly Version: 2.9.0.0

Win32/GenKryptik.GEVR also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GEVR
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
F-SecureTrojan.TR/Crypt.XPACK.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a59c9843d3a223f5
SophosGeneric ML PUA (PUA)
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36196.uF0@aa3hWmoi
VBA32BScope.TrojanPSW.Agent
RisingTrojan.Generic@AI.100 (RDML:22/K/qHmPCY0TpzgCuZTag)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3c1b28
DeepInstinctMALICIOUS

How to remove Win32/GenKryptik.GEVR?

Win32/GenKryptik.GEVR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment