Malware

Win32/GenKryptik.FJNG (file analysis)

Malware Removal

The Win32/GenKryptik.FJNG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FJNG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Behavior consistent with a dropper attempting to download the next stage.
  • The following process appear to have been packed with Themida: DF80E2BAA39DF168DEF0153A2DA053A2.mlw
  • Collects information about installed applications
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bundky32.top
morfug03.top

How to determine Win32/GenKryptik.FJNG?


File Info:

crc32: 63533FA2
md5: df80e2baa39df168def0153a2da053a2
name: DF80E2BAA39DF168DEF0153A2DA053A2.mlw
sha1: 85c6fb34424276b3570c23c48e04552ffa2c1d4f
sha256: 6b7bb728fed4545f0e4b9d3ab78e8f008d78f635d1a9f118a1b962d466c2118d
sha512: 6dbf0a2d4c883c77afa428ef8d36f34b04d0cf2c460d696f78824ee3b55add701cf83651f13679ed801e8a0790fc48181660ef03c798ff5749d19421b6322620
ssdeep: 49152:i26B4s8A+F1PPbpNwOD5iIUJaQVSn0CPW3ABy1n8kyNeC3qRiwQcvqPxB1Y:in8tlTBUgiE0QW3ABE1yNtWQfY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GenKryptik.FJNG also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.TP.aNW@bSUVZzji
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.aa39df
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FJNG
APEXMalicious
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur.TP.aNW@bSUVZzji
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.TP.aNW@bSUVZzji
Ad-AwareGen:Trojan.Heur.TP.aNW@bSUVZzji
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.8998D7021F
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.df80e2baa39df168
EmsisoftGen:Trojan.Heur.TP.aNW@bSUVZzji (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftTrojan.Heur!.032100A1
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Trojan.Heur.TP.aNW@bSUVZzji
AhnLab-V3Trojan/Win.Generic.C4606083
Acronissuspicious
McAfeeArtemis!DF80E2BAA39D
MAXmalware (ai score=83)
VBA32BScope.TrojanBanker.Agent
RisingTrojan.Generic@ML.100 (RDML:jYcBxgNC8Ck9kJ8ZC8/xGQ)
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FJNG?

Win32/GenKryptik.FJNG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment