Malware

Win32/GenKryptik.FKAJ information

Malware Removal

The Win32/GenKryptik.FKAJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FKAJ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

Related domains:

uniderpfm.com.br
ip-api.com
saggiodobrasil.com.br

How to determine Win32/GenKryptik.FKAJ?


File Info:

crc32: 93A129DA
md5: 513f5b2b6d1a1ccd5d43d83ee1304a8a
name: 513F5B2B6D1A1CCD5D43D83EE1304A8A.mlw
sha1: 72e9026f11f47237bed9353f83679e9c36b2a186
sha256: 909224e3ab9525b7ec86a4f85a62fc9a928c791884865d8484a35ee6b086e6e8
sha512: cf58fc2ff6943380e1aeacd031b553e820f241c1824f6c57dd49a1eb83de3571c1cf2ac8c28c9ac9fb5b3d283b19f9eab57529606edceec494ea662a439bf4f1
ssdeep: 98304:YSGwVLvbGjUuxtYwWIUJSZbEb54H3ilzu/hgyrC:vGgg4wAM7HRY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: PDF File
FileDescription: PDF File
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
CompanyName: PDF File
Translation: 0x0409 0x04e4

Win32/GenKryptik.FKAJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Snojan.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.13733
ALYacTrojan.GenericKD.37547600
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Snojan.4599c3d3
K7GWTrojan ( 00581ef41 )
K7AntiVirusTrojan ( 00581ef41 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FKAJ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Snojan.gen
BitDefenderTrojan.GenericKD.37547600
NANO-AntivirusTrojan.Win32.Snojan.jaixxr
MicroWorld-eScanTrojan.GenericKD.37547600
TencentWin32.Trojan.Genkryptik.Sshb
Ad-AwareTrojan.GenericKD.37547600
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.s70@aC9C5zii
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.513f5b2b6d1a1ccd
EmsisoftTrojan.GenericKD.37547600 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34956CB
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Emotet!ml
ArcabitTrojan.Generic.D23CEE50
GDataWin32.Trojan.Agent.N5DEDD
AhnLab-V3Trojan/Win.MalwareX-gen.C4625205
McAfeeArtemis!513F5B2B6D1A
MAXmalware (ai score=81)
VBA32Trojan.Snojan
PandaTrj/Genetic.gen
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
IkarusTrojan-Downloader.Win32.Banload
MaxSecureVirus.Nimnul.E
FortinetPossibleThreat.PALLASNET.H
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FKAJ?

Win32/GenKryptik.FKAJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment