Malware

Win32/GenKryptik.FNCV removal instruction

Malware Removal

The Win32/GenKryptik.FNCV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FNCV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FNCV?


File Info:

crc32: 9B0AC2E0
md5: 8adabded60797216dbeeda89fb069da4
name: 8ADABDED60797216DBEEDA89FB069DA4.mlw
sha1: 0a7bd2fcf04e6b970232c21c1b27bcfe41f0bda4
sha256: d90faa7349876de565e70c9c2252e854d197ab61027d050ee70ec4f3681af073
sha512: 7821e96eef5c3331930f9d1dc39c7f1c0e5eadf7de6684e78572d56d39d6724f104f6ab8c6860ff29941258d2625f71ea7d0bf827bd801c096bb8ffe08fb1f2a
ssdeep: 3072:ByyvI7sFFhfIH+Glj1FZHvP9waIADT5oPSU0vIJfo0u:VI7uhwHlpFZPP9wO3IcI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Cpas
InternalName: Apartheidpolitikerne
FileVersion: 1.00
CompanyName: Kenwoods Cpas
LegalTrademarks: Cpas
Comments: Cpas
ProductName: Cpas
ProductVersion: 1.00
FileDescription: Cpas
OriginalFilename: Apartheidpolitikerne.exe

Win32/GenKryptik.FNCV also known as:

BkavW32.AIDetect.malware2
LionicWorm.Win32.WBVB.o!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/VBKrypt.BCU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNCV
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Worm.Win32.WBVB
BitDefenderTrojan.GenericKD.47336975
ViRobotTrojan.Win32.Z.Wbvb.258048
MicroWorld-eScanTrojan.GenericKD.47336975
Ad-AwareTrojan.GenericKD.47336975
SophosMal/Generic-S + Troj/Zbot-POV
BitDefenderThetaGen:NN.ZevbaF.34266.pm0@aiO5Ffhi
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dh
FireEyeGeneric.mg.8adabded60797216
EmsisoftTrojan.GenericKD.47336975 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Script/Phonzy.C!ml
GDataTrojan.GenericKD.47336975
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeArtemis!8ADABDED6079
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_GEN.F0D1C00K521
IkarusWin32.SuspectCrc
FortinetW32/GenKryptik.FNCV!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/GenKryptik.FNCV?

Win32/GenKryptik.FNCV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment