Malware

Should I remove “Win32/GenKryptik.FJNQ”?

Malware Removal

The Win32/GenKryptik.FJNQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FJNQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FJNQ?


File Info:

crc32: 1C99D84B
md5: e0ed159df2bb6b451816b8b48fd77ccb
name: E0ED159DF2BB6B451816B8B48FD77CCB.mlw
sha1: 129362088a2f298ea4bfc38bcbbbc36b629ee850
sha256: 4ef740da98b7a23dc32bf94dcf2f83aa48285d2c09859e59b456a0f2025b2b35
sha512: c516b05638eb60e9db4e833721cfd01ed92793d2d43bdcaa05aa3287886c24e09096507f86642497a18290f3dedb9aa9d62afa1d9e6c820c1a651f92b32b2212
ssdeep: 6144:r61FoHY1j12PbimfGsE6m4FtWfAvpofL0tJ1PDi7wfaZwln/6kgUB9Z5Dr5kCvj:lcj12PGYEgvIE9Di7orlikjOCvjbD0v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2004
MIMEType: application/x-java-applet;version=1.2|application/x-java-bean;version=1.2|application/x-java-applet;version=1.1.3|application/x-java-bean;version=1.1.3|application/x-java-applet;version=1.1.2|application/x-java-bean;version=1.1.2
FileExtents: |||||
FileVersion: 5.0.60.5
Full Version: 1.5.0_06-b05
FileOpenName: Java Applet|JavaBeans|Java Applet|JavaBeans|Java Applet|JavaBeans
InternalName: Java(TM) Plug-in
ProductName: Java(TM) 2 Platform Standard Edition 5.0 Urdate 6
CompanyName: Sun Microsystems, Inc.
ProductVersion: 5.0.60.5
FileDescription: Java Plug-in 1.5.0_06 for Netscape Navigator (DLL Helper)
OriginalFilename: NPJava12.dll
Translation: 0x0409 0x04e4

Win32/GenKryptik.FJNQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005485311 )
LionicTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005485311 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FJNQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHackTool.Win32.Cobalt.aiz
MicroWorld-eScanTrojan.GenericFCA.Agent.12643
SophosGeneric PUA BC (PUA)
BitDefenderThetaGen:NN.ZexaF.34104.wu0@aKKH!ukP
McAfee-GW-EditionBehavesLike.Win32.Drixed.fc
FireEyeGeneric.mg.e0ed159df2bb6b45
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.02012021
GDataTrojan.GenericFCA.Agent.12643
Acronissuspicious
McAfeeGenericRXAA-AA!E0ED159DF2BB
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3692191579
RisingTrojan.Generic@ML.100 (RDML:tCTTxq+cenGPfNRP/zZQVA)
FortinetPossibleThreat.PALLAS.H
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FJNQ?

Win32/GenKryptik.FJNQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment