Malware

Should I remove “Win32/GenKryptik.CIKS”?

Malware Removal

The Win32/GenKryptik.CIKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CIKS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Uzbek (Latin)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Creates a known Hermes ransomware decryption instruction / key file.

How to determine Win32/GenKryptik.CIKS?


File Info:

name: ECBFD94E5A0F44DF9197.mlw
path: /opt/CAPEv2/storage/binaries/416235b085b6b86640cac3a78f0bd52583eed7154fc3666f5338bde96db10fab
crc32: C838237F
md5: ecbfd94e5a0f44df9197cd6810559084
sha1: 9db4eac9cbf17acc0233f4d5808db8f45eaf7b30
sha256: 416235b085b6b86640cac3a78f0bd52583eed7154fc3666f5338bde96db10fab
sha512: 428491a26a2cbaf54287b73d3e70e82ba9530c2919a83122d7397f09fffb98765970b3810b955fe5a8568cb57163494d84d643546b62f89aafd4f229a67ba388
ssdeep: 6144:77USJR8BPmQxXR+w1rpMuyrQcvFbzA0kMh:U4RSOQiw2rVHXki
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D984AF43A5392940C4910A384BF6C9797AD37E2C7FE69F1631227708B875BE28B73719
sha3_384: 9ba1017947fc8d6dad4c48b6377f9fbb65d89867cc1e32be01c64a86b861a6d75393d3ae084405f19dbfb2c7207ec325
ep_bytes: 6870134000e8f0ffffff000000000000
timestamp: 2018-08-17 03:45:18

Version Info:

Translation: 0x0409 0x04b0
Comments: sAmsUNG
CompanyName: sAmsUNG
FileDescription: sAmsUNG
LegalCopyright: sAmsUNG
LegalTrademarks: sAmsUNG
ProductName: sAmsUNG
FileVersion: 6.03.0005
ProductVersion: 6.03.0005
InternalName: Detruncation4
OriginalFilename: Detruncation4.exe

Win32/GenKryptik.CIKS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Khalesi.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeFareit-FMP!ECBFD94E5A0F
MalwarebytesMachineLearning/Anomalous.95%
SangforRansom.Win32.Hermez.ij
K7AntiVirusTrojan ( 0053aadb1 )
BitDefenderGen:Heur.PonyStealer.ym0@dO60A2hO
K7GWTrojan ( 0053aadb1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Pony.ARE
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GenKryptik.CIKS
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.VBPacked5-6043263-0
KasperskyTrojan-Ransom.Win32.Hermez.ij
AlibabaRansom:Win32/Khalesi.c4399c09
NANO-AntivirusTrojan.Win32.Khalesi.fhruli
ViRobotTrojan.Win32.Ransom.393216.D
MicroWorld-eScanGen:Heur.PonyStealer.ym0@dO60A2hO
RisingDropper.Generic!8.35E (TFE:dGZlOgVKLFi6qMNtWg)
Ad-AwareGen:Heur.PonyStealer.ym0@dO60A2hO
EmsisoftGen:Heur.PonyStealer.ym0@dO60A2hO (B)
ComodoMalware@#25pcwhpp96om
F-SecureHeuristic.HEUR/AGEN.1206731
DrWebTrojan.Encoder.25850
TrendMicroRansom_HERMES.THHAGAH
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.ecbfd94e5a0f44df
SophosMal/Generic-R + Troj/Fareit-FME
IkarusTrojan-Downloader.Win32.Nymaim
GDataGen:Heur.PonyStealer.ym0@dO60A2hO
JiangminTrojan.Khalesi.avy
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1206731
MAXmalware (ai score=100)
ArcabitTrojan.PonyStealer.E590B3
ZoneAlarmTrojan-Ransom.Win32.Hermez.ij
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Hermesran.R234593
VBA32Trojan.Khalesi
ALYacTrojan.Ransom.Hermes
TACHYONRansom/W32.VB-Hermes.393216
CylanceUnsafe
TrendMicro-HouseCallRansom_HERMES.THHAGAH
TencentMalware.Win32.Gencirc.114d3d25
YandexTrojan.GenAsa!PVFCHjRvqBg
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GuLoader.VHJQ!tr
BitDefenderThetaGen:NN.ZevbaF.34638.ym0@aO60A2hO
AVGWin32:Trojan-gen
Cybereasonmalicious.e5a0f4
Paloaltogeneric.ml

How to remove Win32/GenKryptik.CIKS?

Win32/GenKryptik.CIKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment