Malware

Win32/GenKryptik.FJJS removal instruction

Malware Removal

The Win32/GenKryptik.FJJS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FJJS virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

bitbucket.org

How to determine Win32/GenKryptik.FJJS?


File Info:

crc32: 77B7B4B2
md5: dd15ba59f9df4363109fae303521c5f4
name: DD15BA59F9DF4363109FAE303521C5F4.mlw
sha1: 78702cce85903392f566b3918f8eed6830dc1c28
sha256: 5de9e33e8dc270b6ff951c954064725b8bd84e46930b547b1e2bfe9fdbbf3e5b
sha512: e04e098d8381825bb28f0971f871b77e0fa994e98cdc27c5cd1faba5c175f6d8779855c27c423ce387771c1e9bb0c92da10ee6a362b96fce47d1cb415b104569
ssdeep: 12288:YFOedXqMOtzpW5B0UpP7DtnFDpt4kjVYxghEM:KdXqMF5BNP7ZnFtt1Y2hE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x120a 0x0524

Win32/GenKryptik.FJJS also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Fragtor.10553
Cybereasonmalicious.e85903
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FJJS
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Chapak.gen
MicroWorld-eScanGen:Variant.Fragtor.10553
Ad-AwareGen:Variant.Fragtor.10553
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34088.AuW@ay6T1jnK
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.dd15ba59f9df4363
EmsisoftGen:Variant.Fragtor.10553 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_51%
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Fragtor.D2939
GDataGen:Variant.Fragtor.10553
McAfeePacked-GDV!DD15BA59F9DF
MAXmalware (ai score=88)
VBA32BScope.Trojan.Chapak
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/GenKryptik.FJJS?

Win32/GenKryptik.FJJS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment