Malware

About “Win32/GenKryptik.GVRW” infection

Malware Removal

The Win32/GenKryptik.GVRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GVRW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Peru)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/GenKryptik.GVRW?


File Info:

name: AC46EC47D8B64552BA90.mlw
path: /opt/CAPEv2/storage/binaries/f2a7fd78f8505ade73a4bde52794b5e94507cdb5e09bb3140cd3bd08afdad3a8
crc32: B4E38F5A
md5: ac46ec47d8b64552ba90e199321e6ea0
sha1: f7683262367cca2566c6456658b7327d2feed0a9
sha256: f2a7fd78f8505ade73a4bde52794b5e94507cdb5e09bb3140cd3bd08afdad3a8
sha512: fabaa69689e8973ef28ee3c6de42df444cf01090e03e2030681b31e6c0e2eddcb0d3f2cf7ad16026f1559bb9e5282f35fa41f63775c9d47851b60c3088ea07c5
ssdeep: 12288:5TM7T9zE5boV6BGltnmuTyRLpLvrLFEA1IZf9GXf1ATuW5NkV6qKe2/S:5TCW5bo6Gmu2dpLDLaA6h9awdGRK1/S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160F41221B6E0F471C4EBCA3048B8DBB51A797D326A340197A79F277A5F703D08A72746
sha3_384: 6d81c6c8e0d644e939a86b22160ccbc4dcd7b4f849cfa1ced4daaf357512736ee18e04726ccaef1640e036e0cfc6d95d
ep_bytes: e8db410000e989feffff8bff558bec83
timestamp: 2022-10-06 09:14:14

Version Info:

FileVersions: 58.93.75.13
ProductVersion: 95.73.76.15
InternalName: Slupido
LegalCopyrights: sadg asdfg
CompanyNames: sdfg
Translation: 0x5470 0x00a7

Win32/GenKryptik.GVRW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.m5ir
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ac46ec47d8b64552
SkyhighBehavesLike.Win32.Lockbit.bc
McAfeeArtemis!AC46EC47D8B6
Cylanceunsafe
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.GVRW
APEXMalicious
ClamAVWin.Dropper.Glupteba-10025041-0
KasperskyUDS:Trojan-Ransom.Win32.Stop.gen
AvastFileRepMalware [Ransom]
RisingTrojan.SmokeLoader!1.F900 (CLASSIC)
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ADH
SentinelOneStatic AI – Malicious PE
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Znyonm
ZoneAlarmUDS:Trojan-Ransom.Win32.Stop.gen
GoogleDetected
AhnLab-V3Trojan/Win.PWSX-gen.R642038
BitDefenderThetaGen:NN.ZexaF.36802.Tq0@amXnNiV
MalwarebytesMachineLearning/Anomalous.97%
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/GenKryptik.GVRW?

Win32/GenKryptik.GVRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment