Malware

About “Win32/GenKryptik.FKTW” infection

Malware Removal

The Win32/GenKryptik.FKTW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FKTW virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: DE461110D96E1D2689392CAFDE3DA21C.mlw
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FKTW?


File Info:

crc32: C34C91D2
md5: de461110d96e1d2689392cafde3da21c
name: DE461110D96E1D2689392CAFDE3DA21C.mlw
sha1: 95401f52e298ec24d71911c4d6e0184489cdc340
sha256: 71b6b3aaba201e74033fa9f8c27fb6f8f01a47fc52908dd8bb5fe04c97c2e3a3
sha512: bca8511caf8b8efa3b854d23cd247cc9e154a9e9d903ce17767e5a17263405305f037e5fea66cffbdae972ed68e0f8c1c71b6a1e030f93387d0919bc675ae401
ssdeep: 49152:VQco834fFmMHRg2CgFfI9z8bG21Mi6Z/VZLb6Tce:VQWfwgRA48673wce
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2019 (c) Realtek Semiconductor. All rights reserved.
InternalName: RtkNGui.exe
FileVersion: 1.0.703.1
CompanyName: Realtek Semiconductor
ProductName: x745ex6631x9ad8x50b3x771fx97f3x6548
ProductVersion: 1.0.703.1
FileDescription: x745ex6631x9ad8x50b3x771fx97f3x6548
OriginalFilename: RtkNGui.exe
Translation: 0x0404 0x03b6

Win32/GenKryptik.FKTW also known as:

K7AntiVirusTrojan ( 005827a31 )
LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.904711
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/GenKryptik.5043d75f
K7GWTrojan ( 005827a31 )
Cybereasonmalicious.2e298e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FKTW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.MSIL.Reline.hli
BitDefenderGen:Variant.Razy.904711
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.904711
Ad-AwareGen:Variant.Razy.904711
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.de461110d96e1d26
EmsisoftGen:Variant.Razy.904711 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Tnega!ml
GridinsoftTrojan.Heur!.012120B1
ZoneAlarmTrojan-PSW.MSIL.Reline.hli
GDataGen:Variant.Razy.904711
McAfeeArtemis!DE461110D96E
MAXmalware (ai score=81)
VBA32BScope.TrojanSpy.Stealer
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002H09IH21
YandexTrojan.PWS.Reline!iDXTBJL4B38
IkarusTrojan.Win32.Krypt
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FKTW?

Win32/GenKryptik.FKTW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment