Malware

What is “Win32/GenKryptik.FFYV”?

Malware Removal

The Win32/GenKryptik.FFYV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FFYV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

iamfriendz.duckdns.org
iamfriendz.linkpc.net

How to determine Win32/GenKryptik.FFYV?


File Info:

crc32: 1D5523C1
md5: 7464de7805b8bbd5edb32ea464293f58
name: 7464DE7805B8BBD5EDB32EA464293F58.mlw
sha1: 9315c957f4ada9e179af8a46eb1d98d1fdac5f24
sha256: 46ad06ea41612cf4825f35a9e317b0707da66d83b9aad4cf715f69e7ac565f9c
sha512: 634b96941a370e12ba4bef1cdc504ebc29d6b21c12d1cf56b5dabc499211a0f48567cd6b35038a90c006caf7c4efbb7537f27624a91d48653eec8c4add213d88
ssdeep: 12288:ev6Ao2izgP+1tbwAGwu2dyauhnhtpk0fvZK9LTb0ifqjSLGsZGn/XO:evT5W1tbFbdyawVTJKhTbPfqjBsi/+
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/GenKryptik.FFYV also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.46401171
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/GenKryptik.d36115f7
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.805b8b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FFYV
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Remcos.tay
BitDefenderTrojan.GenericKD.46401171
MicroWorld-eScanTrojan.GenericKD.46401171
Ad-AwareTrojan.GenericKD.46401171
SophosMal/Generic-S
ComodoMalware@#3qi92ppd1luro
BitDefenderThetaGen:NN.ZedlaF.34722.Eq4@aG9sZdd
McAfee-GW-EditionBehavesLike.Win32.Vopak.hc
FireEyeGeneric.mg.7464de7805b8bbd5
EmsisoftTrojan.GenericKD.46401171 (B)
AviraTR/Kryptik.hjuem
KingsoftWin32.Hack.Remcos.t.(kcloud)
MicrosoftTrojan:Win32/Remcos.AG!MTB
ArcabitTrojan.Generic.D2C40693
AegisLabWorm.MSIL.Agent.o!c
GDataWin32.Backdoor.Remcos.BC6B43
AhnLab-V3Trojan/Win.Generic.C4499884
McAfeeArtemis!7464DE7805B8
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Remcos
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0DF121
RisingTrojan.Kryptik!1.D6C7 (CLASSIC)
YandexTrojan.Slntscn24.bVVB1s
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.FFYV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FFYV?

Win32/GenKryptik.FFYV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment