Malware

Should I remove “Win32/GenKryptik.AFGA”?

Malware Removal

The Win32/GenKryptik.AFGA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.AFGA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/GenKryptik.AFGA?


File Info:

crc32: D7AC16A5
md5: cd4fdd83b9ea162108223c170c12ac08
name: CD4FDD83B9EA162108223C170C12AC08.mlw
sha1: 0fda7a63b9161a4edf92c5954e3aa21403c91b5f
sha256: 8b580dbda249a44287fc82581265c48f9beea195dd98b71a0d56deb5b078a72d
sha512: 4134b3dde5dea51d2fc33c6dc73cd52e9826b49e02f04d784188f1c1ac22217a30488ad3ed93807e0163bbb3df926cc850a8dc6df9e12d311edda1686eb9a360
ssdeep: 6144:ecyDGRRwGowU02IutSR6H5lZDPnz5j5/N60vIt9S04xwDPr6G:vRRw9wbnzE5bPl5/40vIt9Szxwf6G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999 - 2014 Ashampoo Development GmbH & Co. KG
InternalName: Chess
FileVersion: 3.5.20.8
CompanyName: Ashampoo Development GmbH & Co. KG
FileDescription: Bea Ws Uint_ptr Analytics Memtest Ntds
LegalTrademarks: Copyright xa9 1999 - 2014 Ashampoo Development GmbH & Co. KG
Comments: Bea Ws Uint_ptr Analytics Memtest Ntds
ProductName: Chess
Languages: English
ProductVersion: 3.5.20.8
PrivateBuild: 3.5.20.8
Translation: 0x0409 0x04b0

Win32/GenKryptik.AFGA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0050d6361 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10994
CynetMalicious (score: 85)
ALYacGen:Variant.Ransom.Shade.27
CylanceUnsafe
ZillyaTrojan.SageCrypt.Win32.265
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0050d6361 )
Cybereasonmalicious.3b9ea1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.AFGA
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.SageCrypt.dpn
BitDefenderGen:Variant.Ransom.Shade.27
NANO-AntivirusTrojan.Win32.SageCrypt.eokaml
ViRobotTrojan.Win32.Sage.367616
MicroWorld-eScanGen:Variant.Ransom.Shade.27
TencentMalware.Win32.Gencirc.10bc0c15
Ad-AwareGen:Variant.Ransom.Shade.27
SophosMal/Generic-S
ComodoMalware@#1x5cn2ysdsvg9
BitDefenderThetaGen:NN.ZexaF.34608.wy0@aSDVSjji
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1h
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.cd4fdd83b9ea1621
EmsisoftGen:Variant.Ransom.Shade.27 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128643
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Milicry!bit
ArcabitTrojan.Ransom.Shade.27
AegisLabTrojan.Win32.SageCrypt.j!c
GDataGen:Variant.Ransom.Shade.27
AhnLab-V3Win-Trojan/MalPe33.Suspicious.X2024
Acronissuspicious
McAfeeGenericR-JTR!CD4FDD83B9EA
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Upatre
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-1h
RisingRansom.Milicry!8.A2F2 (TFE:5:FJYuqIO0MxM)
YandexTrojan.SageCrypt!W5XMBqFOTTM
IkarusTrojan.Win32.Krypt
FortinetW32/Generic.AP.D2EBA!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.SageCryp.HgIASOgA

How to remove Win32/GenKryptik.AFGA?

Win32/GenKryptik.AFGA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment