Malware

Win32/GenKryptik.FJIR information

Malware Removal

The Win32/GenKryptik.FJIR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FJIR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
hypercustom.top

How to determine Win32/GenKryptik.FJIR?


File Info:

crc32: F7324820
md5: 5cd5817730e1c989896ca0c89b9afc48
name: 5CD5817730E1C989896CA0C89B9AFC48.mlw
sha1: bd6ad9dec18c94a492744d327ee7ec03d4b0c4c4
sha256: d51dd44a65bdd80d1dfcfb6424668f25933ed52348e0eae8c5beac66b200410c
sha512: db66ce006af1a80c241852d49f80dfd3fbcb27e385da0522abf3069b9d07bc0061a46fed0d3d59e1b31a79cc1b996824516bf33ad8824c2918a13a75564ee7d1
ssdeep: 12288:xogSrPFdVwskfUY3Tl0mSYIvwVVucDGHybL:UrPF0/3SYIvaDXL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x520a 0x0521

Win32/GenKryptik.FJIR also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.34867
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Kryptik.EZJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FJIR
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Brook.gen
BitDefenderTrojan.GenericKD.37453968
MicroWorld-eScanTrojan.GenericKD.37453968
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.5cd5817730e1c989
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_75%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Caynamer.A!ml
GDataWin32.Trojan.Ilgergop.PQINTW
AhnLab-V3Trojan/Win.MalPe.R419570
McAfeePacked-GDV!5CD5817730E1
MAXmalware (ai score=82)
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:MalwareX-gen [Trj]

How to remove Win32/GenKryptik.FJIR?

Win32/GenKryptik.FJIR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment