Malware

How to remove “Win32/GenKryptik.FFQF”?

Malware Removal

The Win32/GenKryptik.FFQF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FFQF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.bing.com
app.buboleinov.com
chat.veminiare.com

How to determine Win32/GenKryptik.FFQF?


File Info:

crc32: 3FDAFAAC
md5: d2fe28f11e61c88847055640d0d92b41
name: D2FE28F11E61C88847055640D0D92B41.mlw
sha1: 63c50a1a754baa987f3853af2f08df9ee86608a7
sha256: b706c4069b014fee3dc18079519e77c9f75e8fc2736264866119a4c0a7bc06c3
sha512: 686919ed208f89a708a1452b2b4df74d8b4c77ce33f7bd079c0ede55c835eeba3917e5d5af44ff7c7ab440da691ea253b99522ffc34b428c8b5ff88b513e1e76
ssdeep: 12288:n7jCgJ8TDXqANCvmA6vdot2lY4ieYHcftQ:nPFSDFNCvmAyot7/Hy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.FFQF also known as:

DrWebTrojan.Gozi.803
CynetMalicious (score: 100)
SangforTrojan.Win32.Cridex.gen
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenKryptik.FFQF
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
BitDefenderTrojan.GenericKD.36937870
ViRobotTrojan.Win32.S.Agent.554496.BA
MicroWorld-eScanTrojan.GenericKD.36937870
Ad-AwareTrojan.GenericKD.36937870
SophosTroj/Dridex-AGY
ComodoMalware@#3kak3wo7tp5v9
BitDefenderThetaGen:NN.ZedlaF.34690.Hu4@aSig!ici
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103EL21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d2fe28f11e61c888
EmsisoftTrojan.GenericKD.36937870 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_88%
MicrosoftTrojan:Win32/Glupteba!ml
AegisLabTrojan.Win32.Cridex.7!c
GDataTrojan.GenericKD.36937870
McAfeeArtemis!D2FE28F11E61
MAXmalware (ai score=81)
VBA32BScope.TrojanBanker.Gozi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103EL21
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusWin32.Outbreak
FortinetW32/GenKryptik.FFPZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FFQF?

Win32/GenKryptik.FFQF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment