Malware

How to remove “Win64/GenKryptik.GBIP”?

Malware Removal

The Win64/GenKryptik.GBIP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/GenKryptik.GBIP virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win64/GenKryptik.GBIP?


File Info:

name: 75ED773F1C56470AA9C2.mlw
path: /opt/CAPEv2/storage/binaries/84bb495d076b128b759c4f8b215c3ca8c57841ba5e9faa8ebc5dc070adf69b16
crc32: 064CB4F1
md5: 75ed773f1c56470aa9c20606214fa7ea
sha1: df1cb5417e2cb0afdab9e3d1cf93b717867ee881
sha256: 84bb495d076b128b759c4f8b215c3ca8c57841ba5e9faa8ebc5dc070adf69b16
sha512: e44f4db8a02c52ca8af78791168dc7878754ab8e081724abcd29ae79ce1a8071b85dec7d6a4d002ed27d3e4de8f4dc50a6c909d8c4863d484094f634ee5c2d1d
ssdeep: 49152:xvWbzVuOtP4ZVrvSdL+CCGFZpjGABwSekyfdYCJrZ6EODOggnWcgc:xkgPvSd6CPj1QHJwzagygc
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T194B5331CD2A61CABC7E1B9F8B19A9D418774C7224C71C3308B6F5277131ABE9F52A64C
sha3_384: 4a8d524cf0b5540bd706786d5fc2743defeeab36ffce87ee2a8732cacfa8d2ffd601a9f07ac62a0a4d7a014b271a44ca
ep_bytes: e9e20300000fb601eb03034c4f48ffc1
timestamp: 2022-06-23 13:14:12

Version Info:

0: [No Data]

Win64/GenKryptik.GBIP also known as:

MicroWorld-eScanTrojan.GenericKD.62967598
McAfeeArtemis!75ED773F1C56
CylanceUnsafe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/GenKryptik.GBIP
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.onfx
BitDefenderTrojan.GenericKD.62967598
AvastWin64:Evo-gen [Trj]
Ad-AwareTrojan.GenericKD.62967598
EmsisoftTrojan.GenericKD.62967598 (B)
McAfee-GW-EditionBehavesLike.Win64.BadFile.vc
Trapminemalicious.high.ml.score
FireEyeTrojan.GenericKD.62967598
GDataWin64.Trojan.Agent.LOL42P
AviraTR/Crypt.Agent.ulssf
Antiy-AVLTrojan/Generic.ASMalwS.50DF
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R525356
MAXmalware (ai score=87)
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Agent!8.B1E (TFE:1:sbrXvAa1ruV)
FortinetW64/GenKryptik.GBIP!tr
AVGWin64:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win64/GenKryptik.GBIP?

Win64/GenKryptik.GBIP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment