Malware

Win32/GenKryptik.FFBA malicious file

Malware Removal

The Win32/GenKryptik.FFBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FFBA virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address

Related domains:

api.ipify.org
158.102.105.176.zen.spamhaus.org
158.102.105.176.cbl.abuseat.org

How to determine Win32/GenKryptik.FFBA?


File Info:

crc32: 25E0E691
md5: 41b25c7d644e4f55d8c2203401ffe249
name: 41B25C7D644E4F55D8C2203401FFE249.mlw
sha1: 5067d9516e46e94abe74e9ddb59fbadc4db839ca
sha256: 9e955c173fcb4383d64ae90a591f1c2e4423f8f546e814041c62a04f7fada83a
sha512: 055ae5ead71b7f156fe8c645ab183384e58e37bfb5eb2043c1b80ae6b801f7fb9945294163d26eff47c0f718c8f0ce33d7531b1b0cf5774f9ad2eb1ce974c429
ssdeep: 12288:bZfAStuSnRmDuGQ9bNfvza04ueQlzxE30wIpgfCORMxVB:h5RmKNfbj4ueQhuEZifCqMxVB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: zlicker_free
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: zlicker_free Application
ProductVersion: 1, 0, 0, 1
FileDescription: zlicker_free MFC Application
OriginalFilename: zlicker_free.EXE
Translation: 0x0409 0x04b0

Win32/GenKryptik.FFBA also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.15953
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.75025
CylanceUnsafe
SangforTrojan.Win32.Trickbot.GKM
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Trickbot.3883d6c8
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.EBG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FFBA
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Fhcu-9859680-0
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKDZ.75025
MicroWorld-eScanTrojan.GenericKDZ.75025
Ad-AwareTrojan.GenericKDZ.75025
SophosMal/Generic-R + Troj/Trickb-M
TrendMicroTROJ_GEN.R002C0WEA21
McAfee-GW-EditionTrickbot-FTPR!41B25C7D644E
FireEyeGeneric.mg.41b25c7d644e4f55
EmsisoftTrojan.GenericKDZ.75025 (B)
AviraTR/AD.Emotet.towbh
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Trickbot.GKM!MTB
GridinsoftTrojan.Win32.Banker.oa!s1
ArcabitTrojan.Generic.D12511
AegisLabTrojan.Win32.Trickpak.4!c
ZoneAlarmHEUR:Trojan.Win32.Trickpak.gen
GDataTrojan.GenericKDZ.75025
AhnLab-V3Trojan/Win.Agent.C4455757
McAfeeArtemis!41B25C7D644E
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0WEA21
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.Trickpak!PIEKDcxyMAI
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.109946090.susgen
FortinetW32/GenKryptik.FFBA!tr
AVGWin32:BankerX-gen [Trj]

How to remove Win32/GenKryptik.FFBA?

Win32/GenKryptik.FFBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment