Malware

About “Win32/GenKryptik.FJNZ” infection

Malware Removal

The Win32/GenKryptik.FJNZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FJNZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
edgedl.me.gvt1.com

How to determine Win32/GenKryptik.FJNZ?


File Info:

crc32: DC7A4DBB
md5: 4cfe5d56e69b49b12c674465a4330700
name: 4CFE5D56E69B49B12C674465A4330700.mlw
sha1: 3d2a20ddd27587d4f988865b27d22b011fb746bc
sha256: 848813fa2c1bf4b2ae9cce84ba9fafdb5349f9b81c838ea3cf537f7e83e34109
sha512: 66c1c9dbac3b6a7311893fbe0a37e09276d8ffbb69914fa8a6c7e67ab4c2768d0ba3beabe41b2aeb63b5f25c958e4c3b8054419713630d7dfdb266116b2c5889
ssdeep: 12288:h6ADUjB4J59b3zkpFnNMO1i33PCijWdQcec:h6I9bDu3bM3qiKQc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.aci
ProductVersion: 7.59.25.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Win32/GenKryptik.FJNZ also known as:

K7AntiVirusTrojan ( 0056f9be1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.31061
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FJNZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Zenpak.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34104.Cq0@aiuxjYmG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
FireEyeGeneric.mg.4cfe5d56e69b49b1
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.STOP.ko!se1076
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataWin32.Trojan-Stealer.Racealer.IT9CRS
Acronissuspicious
McAfeePacked-GDT!4CFE5D56E69B
VBA32BScope.TrojanRansom.Blocker
MalwarebytesMachineLearning/Anomalous.96%
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
IkarusWin32.Outbreak
FortinetW32/Mal_HPGen.50
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FJNZ?

Win32/GenKryptik.FJNZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment