Malware

Mal/Generic-S + Troj/Krypt-FM removal guide

Malware Removal

The Mal/Generic-S + Troj/Krypt-FM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Krypt-FM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • CAPE detected the WinDealer malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
www.360.cn
icanhazip.com

How to determine Mal/Generic-S + Troj/Krypt-FM?


File Info:

name: 3CA9D63BDD01A83DD5E3.mlw
path: /opt/CAPEv2/storage/binaries/82035910faffe8343bf749f19a31b46c14437681ae43e9304eac0233f906efd1
crc32: 33B87137
md5: 3ca9d63bdd01a83dd5e342f97ee2186d
sha1: e66019b79ec5d2f648d8e81ef3867957eec6b021
sha256: 82035910faffe8343bf749f19a31b46c14437681ae43e9304eac0233f906efd1
sha512: d8f3f8a59ceb997b5e871e5dc69bef2684e3e508a38b6fd5427b6d4bc97f8262ba7394691f7a374f805798e31187ea2944c1537fcd0a2287ffe75b678f91ecef
ssdeep: 3072:n8CIwLqrMhDmfY43Q9dmmeixZQIPtm1ap2kyk3iXiJ0gkjkgUJslVvp1g:Sw+MhDmf93I3tm1ap2rdXimfRle
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D848D65B126E45CDAA50DF81EE4FEBD236D5D221C2C18826E2CF38CBA35E937E44534
sha3_384: 5769f64b40462f6f171cbc37950564cbfaa4d3b096f91bf531ff157a87de0769fcef4925942019c1ea532c9d8299fef4
ep_bytes: 558bec6aff687034400068b621400064
timestamp: 2018-05-24 01:56:53

Version Info:

CompanyName:
FileDescription: RunResDll Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: RunResDll
LegalCopyright: 版权所有 (C) 2018
LegalTrademarks:
OriginalFilename: RunResDll.EXE
ProductName: RunResDll 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Mal/Generic-S + Troj/Krypt-FM also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.3725
MicroWorld-eScanGen:Variant.Strictor.264540
FireEyeGeneric.mg.3ca9d63bdd01a83d
CAT-QuickHealTrojan.GenericRI.S23839443
ALYacGen:Variant.Strictor.264540
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2579893
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.4d9dd004
K7GWTrojan ( 0054e0a31 )
K7AntiVirusTrojan ( 0054e0a31 )
BitDefenderThetaGen:NN.ZexaF.34084.yq0@aeatDvbb
CyrenW32/Zusy.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GHFL
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.qwidcl
BitDefenderGen:Variant.Strictor.264540
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.100 (RDML:Azrldlgy2GcQGBv9DFgGrA)
Ad-AwareGen:Variant.Strictor.264540
TACHYONTrojan/W32.Agent.393216.AQA
EmsisoftGen:Variant.Strictor.264540 (B)
ComodoWorm.Win32.Prux.A@4q442u
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionTrojan-FPZA!3CA9D63BDD01
SophosMal/Generic-S + Troj/Krypt-FM
IkarusTrojan.Crypt
JiangminTrojan.Agent.bwin
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1111322
Antiy-AVLTrojan/Generic.ASMalwS.26900A4
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Strictor.264540
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R419093
Acronissuspicious
McAfeeTrojan-FPZA!3CA9D63BDD01
MAXmalware (ai score=87)
VBA32Trojan.Fuerboos
MalwarebytesMalware.AI.1531853078
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
TencentMalware.Win32.Gencirc.10b1fe67
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74195037.susgen
FortinetW32/Kryptik.GHFL!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.bdd01a
PandaTrj/GdSda.A

How to remove Mal/Generic-S + Troj/Krypt-FM?

Mal/Generic-S + Troj/Krypt-FM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment