Malware

How to remove “Win32/GenKryptik.FAKR”?

Malware Removal

The Win32/GenKryptik.FAKR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FAKR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

c8dd8ae6dc4dc644.xyz

How to determine Win32/GenKryptik.FAKR?


File Info:

crc32: C7710771
md5: f7d7c89f3f5cbc925480b46b7b934157
name: F7D7C89F3F5CBC925480B46B7B934157.mlw
sha1: 73e389b70cf3d8975ccbaf7d04f4c45cc80be860
sha256: 2870f899f2e9ec540da321f603cfb1a735dcd06df016718e663dc78fefdf5e0a
sha512: 9b972e2954c18f706a6f8012a6b76e1f4ce8e76466eae919b55a6225c4f8574586d9f11838d8d63bdd245b11cfd3e581248e9a578f72ff2dd8b6623bebc525eb
ssdeep: 98304:LWrSa24w3rQ/pE/JFBCnpcYiKAEXXPnsNSkUe:iy4wesJFqpc8dXfUSe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2008
InternalName: Google Pinyin
FileVersion: 2.7.25.128
CompanyName: Google Inc.
ProductName: Google Pinyin IME
ProductVersion: 2.7.25.128
FileDescription: Google Pinyin IME
Translation: 0x0804 0x04b0

Win32/GenKryptik.FAKR also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Babar.22371
FireEyeGeneric.mg.f7d7c89f3f5cbc92
ALYacGen:Variant.Babar.22371
CylanceUnsafe
BitDefenderGen:Variant.Babar.22371
Cybereasonmalicious.f3f5cb
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Backdoor.Win32.Poison.vho
RisingTrojan.Generic@ML.93 (RDML:mAfg96w8gwlXlZRtqFsgyA)
Ad-AwareGen:Variant.Babar.22371
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
EmsisoftGen:Variant.Babar.22371 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.D2!ml
ArcabitTrojan.Babar.D5763
ZoneAlarmHEUR:Backdoor.Win32.Poison.vho
GDataGen:Variant.Babar.22371
CynetMalicious (score: 100)
McAfeeArtemis!F7D7C89F3F5C
MAXmalware (ai score=80)
ESET-NOD32a variant of Win32/GenKryptik.FAKR
IkarusTrojan.Win32.Krypt
AVGFileRepMalware

How to remove Win32/GenKryptik.FAKR?

Win32/GenKryptik.FAKR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment