Malware

Win32/GenKryptik.FLAA malicious file

Malware Removal

The Win32/GenKryptik.FLAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FLAA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.

How to determine Win32/GenKryptik.FLAA?


File Info:

crc32: 44E9F8B3
md5: 015ba9cc568b35e6687ec4a8ac61dc15
name: 015BA9CC568B35E6687EC4A8AC61DC15.mlw
sha1: 3fd792fd8807b9302be94d068304d820c1c671ca
sha256: 944c18692e200c4de70817facee4fd8662c99743d64e57e43dd3f212d68e8003
sha512: 179c69bb13b0cc9907f05feb84cb7b3be2c7cf151a653600a0e9c0b38543ea3c2db920bd527dccf2eb8457e8dbc895518568bb04adf09b9218f46773d8c30aab
ssdeep: 6144:tIl3f5on8R0CBtsabvbC0iRugpw8mI3R5y4MAIJ+CczfBsx2X/HSpu9SiWaKMVe:tk32q0CB5Mwq6cBsxsPUmYa1B3js
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: Pizza
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Pizza Application
ProductVersion: 1, 0, 0, 1
FileDescription: Pizza MFC Application
OriginalFilename: Pizza.EXE
Translation: 0x0409 0x04b0

Win32/GenKryptik.FLAA also known as:

LionicTrojan.Win32.Trickpak.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GenKryptik.FLAA
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKD.47018190
MicroWorld-eScanTrojan.GenericKD.47018190
SophosML/PE-A
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.015ba9cc568b35e6
EmsisoftTrojan.GenericKD.47018190 (B)
SentinelOneStatic AI – Suspicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Trickbot.AT
ZoneAlarmHEUR:Trojan.Win32.Trickpak.gen
GDataWin32.Trojan-Spy.TrickBot.MG3L55
McAfeeRDN/Generic
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.YXBIWZ
IkarusWin32.Outbreak
FortinetW32/GenKryptik.FLAA!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FLAA?

Win32/GenKryptik.FLAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment