Malware

Win32/GenKryptik.GNTI removal tips

Malware Removal

The Win32/GenKryptik.GNTI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GNTI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenKryptik.GNTI?


File Info:

name: 0FD09CBEF7CCEB3445C2.mlw
path: /opt/CAPEv2/storage/binaries/1dce2f630656d4ac512c39285e4716bd23234bd22da3888e62c5d128b5acd9e2
crc32: C8CBF768
md5: 0fd09cbef7cceb3445c2deccdaa22ee7
sha1: d2009c16e6699eac805726b69cf24a25ecadef5c
sha256: 1dce2f630656d4ac512c39285e4716bd23234bd22da3888e62c5d128b5acd9e2
sha512: 6550e5b7d49eceef13bc27ee7c8b7b57a2aaa3ace5c264bd172ab3f7c82cc5cdc48504054af659cee2710992d9ed8de59ae8356c1bf514d6736ee7afa5b58c60
ssdeep: 12288:cLAu0HYnU4/TbIP2v0Hw1Y2Cs4DQDgIDT5eYles:cFqo9/Iev0Q1YXbUDgIDYaes
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T143B4C0163BF58877D6031136CF6DABD5A4FAE26D4C20494327C41D6CFA39DC6D228A2E
sha3_384: 4d4c7949cd46cf957c164a0b5a41be0b992ed711f095e9fc951d790bf55a665712cb78d22c0341be1b03078972492c32
ep_bytes: 558bec6aff6840ce430068b03d430064
timestamp: 2018-12-30 11:23:52

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7-Zip Console
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.exe
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

Win32/GenKryptik.GNTI also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Jaik.173903
FireEyeGen:Variant.Jaik.173903
ALYacGen:Variant.Jaik.173903
VIPREGen:Variant.Jaik.173903
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.36662.Fy0@aCbnRCpi
CyrenW32/Injuke.BI.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GNTI
APEXMalicious
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderGen:Variant.Jaik.173903
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
EmsisoftGen:Variant.Jaik.173903 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A
GDataGen:Variant.Jaik.173903
GoogleDetected
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Jaik.D2A74F
ZoneAlarmHEUR:Trojan.Win32.Injuke.gen
MicrosoftProgram:Win32/Wacapew.C!ml
AhnLab-V3Malware/Win.Generic.C5482209
VBA32BScope.Backdoor.Sinowal
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:KoKHFJJMYIdnTLohKGiHTQ)
FortinetAdware/Adware_AGen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Win32/GenKryptik.GNTI?

Win32/GenKryptik.GNTI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment