Malware

Mal/Generic-R + Troj/Krypt-FM removal tips

Malware Removal

The Mal/Generic-R + Troj/Krypt-FM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Krypt-FM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • CAPE detected the WinDealer malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

How to determine Mal/Generic-R + Troj/Krypt-FM?


File Info:

name: A4C18AABC5FA8869FBF9.mlw
path: /opt/CAPEv2/storage/binaries/aeb217d174e7a7c2078010323e22d79724c98553eaa15025301c908967ed05a2
crc32: 692EC73A
md5: a4c18aabc5fa8869fbf9070a4da9adb5
sha1: 6317e152b4798a1e304e496d1a4fef4a2860cac2
sha256: aeb217d174e7a7c2078010323e22d79724c98553eaa15025301c908967ed05a2
sha512: 7ec600c39dd449d95aba46e4ffbd133174785deed6d964540f0242ab4b13f0248e43a6687979bf2c21d108dd6d982145264234415de4aa5390d0e8ca78da7f4a
ssdeep: 3072:n8CiD4bwenIp4L6J2+UV8GZk1MdTLDO/cELwR1Erwfod64fP:UD4Een04L6HU3Z9DO/hUR1jod6SP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100848D317087CABED1B604742E16C9FD225D3D21EC0D4B23674C3BAC9F7B6624E19A69
sha3_384: f09e7fea154bed8f4ab161447eb77dd190e5b01c5533a04bfe3d8ebb6038d3c887f497d306bf51210ee01fe38c587050
ep_bytes: 558bec6aff687034400068b621400064
timestamp: 2018-05-24 01:56:53

Version Info:

CompanyName:
FileDescription: RunResDll Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: RunResDll
LegalCopyright: 版权所有 (C) 2018
LegalTrademarks:
OriginalFilename: RunResDll.EXE
ProductName: RunResDll 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Mal/Generic-R + Troj/Krypt-FM also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a4c18aabc5fa8869
ALYacGen:Variant.Strictor.264540
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054e0a31 )
BitDefenderGen:Variant.Strictor.264540
K7GWTrojan ( 0054e0a31 )
Cybereasonmalicious.bc5fa8
CyrenW32/Zusy.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GHFL
APEXMalicious
KasperskyTrojan.Win32.Agent.qwidcl
MicroWorld-eScanGen:Variant.Strictor.264540
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazoDOuV2WDLYZxAYG/0MWAas)
Ad-AwareGen:Variant.Strictor.264540
SophosMal/Generic-R + Troj/Krypt-FM
ComodoWorm.Win32.Prux.A@4q442u
DrWebTrojan.PWS.Siggen2.3725
McAfee-GW-EditionTrojan-FPZA!A4C18AABC5FA
EmsisoftGen:Variant.Strictor.264540 (B)
IkarusTrojan.Crypt
JiangminTrojan.Agent.bwin
AviraHEUR/AGEN.1111322
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.26900A4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Strictor.264540
AhnLab-V3Trojan/Win.Generic.R419093
Acronissuspicious
McAfeeTrojan-FPZA!A4C18AABC5FA
TACHYONTrojan/W32.Agent.393216.AQA
VBA32Trojan.Fuerboos
MalwarebytesMalware.AI.3234456570
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.10b1fe67
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.GHFL!tr
BitDefenderThetaGen:NN.ZexaF.34182.yq0@aeatDvbb
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Generic-R + Troj/Krypt-FM?

Mal/Generic-R + Troj/Krypt-FM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment