Categories: Malware

What is “Win32/GenKryptik.FCQA”?

The Win32/GenKryptik.FCQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FCQA virus can do?

  • A process created a hidden window
  • Attempts to delete volume shadow copies
  • Enumerates services, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/GenKryptik.FCQA?


File Info:

crc32: A81B6285md5: 0e458dd198349974739a77b1e07c0273name: 0E458DD198349974739A77B1E07C0273.mlwsha1: 0b8b251baf373710621b73748af769fe73d753afsha256: ecda215fa5c255971320d6d8e0eff87b38d7a724fcd41afacdcff1d73fe8c7ebsha512: f0ad21a2d4b327486fb1a9b4017e43df77a3cef2efa2e1d82d799a9e0b600caa40127e0b2a12d0b7d79d8b714b8968286f25f4bc3d9f2e44165aa833c9a278e8ssdeep: 768:HSyi2XMhdX13mJiEYvqv7DZ4X2ixOqvf5fPhCqMEOx1XHQJ:HSyi+MhEYcDZCXx3fJ/MpXtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 1995-2019 McAfee, Inc. All Rights Reserved.FileVersion: MALWCLEANER.13.1.0.4103CompanyName: McAfee, Inc.FileDescription: McAfee Malware CleanerProductName: MALWCLEANERProductVersion: 13.1.0.130PrivateBuild: MALWCLEANER.13.1.0.4103Translation: 0x0000 0x04b0

Win32/GenKryptik.FCQA also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
ALYac Gen:Variant.Razy.506133
Cylance Unsafe
Sangfor Trojan.Win32.DelShad.ky
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Ransom:Win32/Cerber.f232f89e
K7GW Trojan ( 0057a54e1 )
Cybereason malicious.198349
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FCQA
APEX Malicious
Avast Win32:Trojan-gen
Kaspersky UDS:Trojan.Win32.DelShad
BitDefender Gen:Variant.Razy.506133
MicroWorld-eScan Gen:Variant.Razy.506133
Ad-Aware Gen:Variant.Razy.506133
Sophos ML/PE-A + Mal/EncPk-ZC
BitDefenderTheta Gen:NN.ZexaF.34670.cu0@a0y666fi
McAfee-GW-Edition BehavesLike.Win32.Generic.ph
FireEye Generic.mg.0e458dd198349974
Emsisoft Gen:Variant.Razy.506133 (B)
SentinelOne Static AI – Suspicious PE
Webroot W32.DelShad
Avira TR/Crypt.XPACK.Gen
Microsoft Ransom:Win32/Cerber.L!bit
Arcabit Trojan.Razy.D7B915
AegisLab Trojan.Win32.DelShad.4!c
GData Gen:Variant.Razy.506133
McAfee Artemis!0E458DD19834
MAX malware (ai score=81)
Panda Trj/GdSda.A
TrendMicro-HouseCall Ransom_Cerber.R002C0DD721
Rising Ransom.Cerber!8.3058 (CLOUD)
Ikarus Win32.Outbreak
Fortinet W32/GenKryptik.FCQA!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
Qihoo-360 Win32/Ransom.Cerber.HxQBbqcA

How to remove Win32/GenKryptik.FCQA?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “MSIL/TrojanDropper.Agent.BVT”?

The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

16 hours ago

Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

16 hours ago

Malware.AI.524217860 removal tips

The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

17 hours ago

Trojan:Win32/Koutodoor.F removal tips

The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

18 hours ago

How to remove “Malware.AI.1412460714”?

The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

18 hours ago

Generic.Dacic.8952383F.A.5EC8C34B removal instruction

The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

18 hours ago