Malware

How to remove “Win32/GenKryptik.FEWM”?

Malware Removal

The Win32/GenKryptik.FEWM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FEWM virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
app.buboleinov.com
chat.veminiare.com
chat.billionady.com

How to determine Win32/GenKryptik.FEWM?


File Info:

crc32: E2CF371F
md5: 9debcd929765390555ca123c0076eea4
name: 9DEBCD929765390555CA123C0076EEA4.mlw
sha1: d0c68d1d874a877dbbbce1fea0bb164c6bdad642
sha256: 9969cfd81612d1efbc5e983b57ff2fa2a69a3f6a6812c6da8382bf0c22014cf4
sha512: 6c81556e2438ee04d5fae0e0b069d1558c2ab0fa2023915dad80203cca62b16f6dcf797bd58c854cfa5fdb113bf831cf2f7a040a287a66efa9637f64c35fd9ab
ssdeep: 6144:ZUQrm4xMOQVFUy/kLYFnEaynGFa7ygc8eY:ZUelqO0REa2G0egJ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Termwide Corporation. All rights reserved
InternalName: Go
FileVersion: 2.3.6.358
CompanyName: Termwide Corporation
ProductName: Termwidexae Grass firexae
ProductVersion: 2.3.6.358
FileDescription: Termwide Grass fire Untilsuccess
OriginalFilename: Flower.dll
Translation: 0x0409 0x04b0

Win32/GenKryptik.FEWM also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.36852105
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
AlibabaTrojan:Win32/GenKryptik.285c17e3
K7GWTrojan ( 0057bfe91 )
K7AntiVirusTrojan ( 0057bfe91 )
CyrenW32/Trojan.SDHP-0290
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GenKryptik.FEWM
AvastWin32:Trojan-gen
BitDefenderTrojan.GenericKD.36852105
MicroWorld-eScanTrojan.GenericKD.36852105
Ad-AwareTrojan.GenericKD.36852105
SophosMal/Generic-S (PUA)
ComodoTrojWare.Win32.UMal.favcq@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Gozi_Ifsb
FireEyeTrojan.GenericKD.36852105
EmsisoftTrojan.Agent (A)
WebrootW32.Trojan.Gen
AviraTR/AD.UrsnifDropper.csjut
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.36852105
McAfeeArtemis!9DEBCD929765
MAXmalware (ai score=81)
VBA32BScope.TrojanBanker.Cridex
MalwarebytesTrojan.Ursnif
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan.Win32.Krypt
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen

How to remove Win32/GenKryptik.FEWM?

Win32/GenKryptik.FEWM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment