Malware

Win32/GenKryptik.FFNF removal guide

Malware Removal

The Win32/GenKryptik.FFNF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FFNF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

ident.me
apps.identrust.com
www.myexternalip.com
158.102.105.176.zen.spamhaus.org
158.102.105.176.cbl.abuseat.org
158.102.105.176.b.barracudacentral.org
158.102.105.176.dnsbl-1.uceprotect.net
158.102.105.176.spam.dnsbl.sorbs.net

How to determine Win32/GenKryptik.FFNF?


File Info:

crc32: E2CA2CC7
md5: 8d81757dd2b9cde3b02381ee23345327
name: 8D81757DD2B9CDE3B02381EE23345327.mlw
sha1: 531b56975796a80c0b88bcdffa8e44d8637d1a72
sha256: 4705a187238b7c9c83cd30537bb13033e10003d80e2780a71c2b0883f2d3594d
sha512: f6ed55b2d374dc51f7fb7c93241e1af15e8c052711e82c65820b4bbd577a096e9e1bc413175c037ac96e84edbf123e7269eb3ef2a0e4d22f300ee717060afe28
ssdeep: 12288:AbMr9Z/ztemee414FB4ycKSHtqAYLHVa+SbwwG:AbaZ/zv414hRSHiHAhbzG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: kromptEdit_Demo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: kromptEdit_Demo Application
ProductVersion: 1, 0, 0, 1
FileDescription: kromptEdit_Demo MFC Application
OriginalFilename: kromptEdit_Demo.EXE
Translation: 0x0409 0x04b0

Win32/GenKryptik.FFNF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057c6291 )
DrWebTrojan.KillProc2.16029
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.75200
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0057c6291 )
CyrenW32/Agent.CXC.gen!Eldorado
ESET-NOD32a variant of Win32/GenKryptik.FFNF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Fhnx-9861300-0
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKDZ.75200
NANO-AntivirusTrojan.Win32.Trickpak.ivhlcf
MicroWorld-eScanTrojan.GenericKDZ.75200
Ad-AwareTrojan.GenericKDZ.75200
SophosML/PE-A + Troj/Trickb-S
McAfee-GW-EditionGenericRXON-SD!8D81757DD2B9
FireEyeGeneric.mg.8d81757dd2b9cde3
EmsisoftTrojan.GenericKDZ.75200 (B)
JiangminTrojan.Trickpak.ec
AviraTR/AD.Emotet.fpuat
MicrosoftTrojan:Win32/Trickbot.VIS!MTB
GridinsoftMalware.Win32.Gen.oa!s1
ArcabitTrojan.Generic.D125C0
GDataWin32.Trojan.PSE.YPZFWR
AhnLab-V3Trojan/Win.TrickBot.R420693
MAXmalware (ai score=81)
VBA32Trojan.Trickpak
MalwarebytesTrojan.TrickBot
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.FFIF!tr
AVGWin32:Malware-gen

How to remove Win32/GenKryptik.FFNF?

Win32/GenKryptik.FFNF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment