Malware

Win32/Kryptik.GENU information

Malware Removal

The Win32/Kryptik.GENU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GENU virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ec2-52-57-16-9.eu-central-1.compute.amazonaws.com
illumex.ai

How to determine Win32/Kryptik.GENU?


File Info:

crc32: 56B2C90B
md5: 253cdd50b39ba76e677c6d7e921050af
name: 253CDD50B39BA76E677C6D7E921050AF.mlw
sha1: e203b3591fb77b7d98db0ba0a1b72cbceb4a1f19
sha256: 1a2eee97afe625d5e1b1aca6c4bc1fe80b769dbb9ee47b9ac6a40a708b047d82
sha512: 30904104d71d8823f9f333659716d26dc31b669455aa293727efcc2607dd4785942212a18450076ef4c530eb285613176c024de8b5708f3f1d01f83bcaa3ba5f
ssdeep: 49152:3kOL736M2lYtL0ET8WfATyvcO4z1Pq3eAQTjPwd:3kOL7N2lAAGvcOuPq3eAIjId
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductName: McAfee Safe Connect
ProductVersion: 1.0
FileDescription: McAfee Safe Connect Installer
FileVersion: 1.0
CompanyName: McAfee
Translation: 0x0409 0x04b0

Win32/Kryptik.GENU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00533b5a1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3282
CynetMalicious (score: 100)
ALYacTrojan.Mint.Zamg.J
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3130265
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0052b8be1 )
Cybereasonmalicious.0b39ba
CyrenW32/Kryptik.CNC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GENU
APEXMalicious
AvastWin32:AdwareSig [Adw]
ClamAVWin.Dropper.Icloader-6553203-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Mint.Zamg.J
NANO-AntivirusTrojan.Win32.SelfDel.eyzurs
MicroWorld-eScanTrojan.Mint.Zamg.J
TencentMalware.Win32.Gencirc.10c8e97b
Ad-AwareTrojan.Mint.Zamg.J
SophosMal/Generic-S + Mal/BadCert-Gen
ComodoApplication.Win32.ICLoader.GS@84429a
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.ICLOADER.SM
McAfee-GW-EditionPacked-VJ!253CDD50B39B
FireEyeGeneric.mg.253cdd50b39ba76e
EmsisoftApplication.AdFile (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mmri
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.250B898
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Mint.Zamg.J
GDataTrojan.Mint.Zamg.J
AhnLab-V3PUP/Win32.ICLoader.R223029
Acronissuspicious
McAfeePacked-VJ!253CDD50B39B
MAXmalware (ai score=95)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ICLOADER.SM
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
YandexTrojan.GenAsa!mS1/ROmWQOs
IkarusPUA.FileTour
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GENU?

Win32/Kryptik.GENU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment