Malware

Win32/GenKryptik.FLQH information

Malware Removal

The Win32/GenKryptik.FLQH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FLQH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.FLQH?


File Info:

name: A29CC043A19E6FB512EC.mlw
path: /opt/CAPEv2/storage/binaries/3f4f8fa7b16d25a752e9608f3063b802c2da10809791eecb29216f0e638221fe
crc32: 07998386
md5: a29cc043a19e6fb512ecd3004aa47f2f
sha1: c82f2bbed325bbb5f7c806589fd47fe8b8afb9ef
sha256: 3f4f8fa7b16d25a752e9608f3063b802c2da10809791eecb29216f0e638221fe
sha512: 9f411fc1fbbc39868a4af93a24fc1df47a9943e074ae88ea8692afd3a6c8636f4476b192ae8d5c5118c769b9ce8f92b2d3ee5fb50435df76a6375083352a464d
ssdeep: 768:Eh9F57QpLLE0rR1xxfXHUcriK2Rf1aJ1RC:cn57Q20VNsuiK2mK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118C2C086E7CD8C2AD891517946679B415F28FC1E82664F5F0A04FE9D3C34BA0AD723F8
sha3_384: e6d753ac08bc174d44f70ec595381bb4181057535d9583285f3a81a60cb6eb2dfd256927e3f3166c74f96c8d7c138003
ep_bytes: 60be00b040008dbe0060ffff5783cdff
timestamp: 2021-10-05 02:50:36

Version Info:

CompanyName:
FileDescription: BitmapPave Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: BitmapPave
LegalCopyright: 版权所有 (C) 2002
LegalTrademarks:
OriginalFilename: BitmapPave.EXE
ProductName: BitmapPave 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Win32/GenKryptik.FLQH also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.a29cc043a19e6fb5
McAfeeArtemis!A29CC043A19E
CylanceUnsafe
K7AntiVirusTrojan ( 004bb7241 )
AlibabaTrojanDownloader:Win32/Zegost.ea09d39c
K7GWTrojan ( 004bb7241 )
Cybereasonmalicious.ed325b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FLQH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.47619048
MicroWorld-eScanTrojan.GenericKD.47619048
AvastWin32:Trojan-gen
TencentWin32.Trojan.Injuke.Llqy
Ad-AwareTrojan.GenericKD.47619048
EmsisoftTrojan.GenericKD.47619048 (B)
TrendMicroTROJ_GEN.R002C0DLA21
McAfee-GW-EditionGenericRXQJ-LZ!67FF8B5E9F42
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.WZTQT4
JiangminTrojan.PSW.Magania.bfs
AviraHEUR/AGEN.1108344
Antiy-AVLTrojan/Generic.ASMalwS.34AB4DB
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D69BE8
MicrosoftTrojanDownloader:Win32/Zegost.E!bit
BitDefenderThetaGen:NN.ZexaF.34084.bmKfa4ocxwib
MAXmalware (ai score=80)
VBA32TrojanDownloader.Zegost
MalwarebytesWorm.Magania
TrendMicro-HouseCallTROJ_GEN.R002C0DLA21
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.FLTT!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Win32/GenKryptik.FLQH?

Win32/GenKryptik.FLQH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment