Malware

Should I remove “Win32/GenKryptik.FARL”?

Malware Removal

The Win32/GenKryptik.FARL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FARL virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.FARL?


File Info:

crc32: D986E121
md5: b048ee8597ab47764b81b77ebddf2020
name: B048EE8597AB47764B81B77EBDDF2020.mlw
sha1: 5fc26626854e51ece6ae33a4db28b38e8ad4fb7f
sha256: d4a393de8d40fa7cb46d6f37169f10936cbc79b23f6b656e74aafb01975125f3
sha512: 368a7c2ee7bcc4b6d9ef0d65318603fcc417df6fda3885e1f5346ab82f18e0e17fc993ed9c1ba37c1e3133ac21f148ac89cfffa541a757b1952cb5f71707f1ee
ssdeep: 12288:3ZIit+/vmLXD6KxM9ehG/hIgVJG77PQ8Az6iHs77juXK:3ZZAWLT6K29eh4xbG77I8M6i+71
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2012 Rainexcept Corporation. All rights reserved
Flat: Moon were
InternalName: bought.dll
FileVersion: 8.1.3.825
CompanyName: Rainexcept
ProductName: Rainexcept Winter raise
ProductVersion: 8.1.3.825
FileDescription: Winter raise
OriginalFilename: bought.dll
Translation: 0x0409 0x04b0

Win32/GenKryptik.FARL also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
McAfeeGenericRXAA-AA!B048EE8597AB
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
BitDefenderTrojan.GenericKD.36257196
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Agent.FCOE
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.gen
MicroWorld-eScanTrojan.GenericKD.36257196
Ad-AwareTrojan.GenericKD.36257196
EmsisoftTrojan.GenericKD.36257196 (B)
F-SecureTrojan.TR/AD.Dridex.wab
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.b048ee8597ab4776
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Dridex.wab
MAXmalware (ai score=83)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.gen
GDataTrojan.GenericKD.36257196
VBA32BScope.Trojan.Ursnif
ESET-NOD32a variant of Win32/GenKryptik.FARL
TrendMicro-HouseCallTROJ_FRS.VSNTAS21
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.FARL!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Win32/GenKryptik.FARL?

Win32/GenKryptik.FARL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment