Malware

Win32/GenKryptik.FNWX information

Malware Removal

The Win32/GenKryptik.FNWX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FNWX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

Related domains:

wpad.local-net
advanceddiplomaaviation.com

How to determine Win32/GenKryptik.FNWX?


File Info:

name: 95EEB9A5973BC5AF2860.mlw
path: /opt/CAPEv2/storage/binaries/f5d10e74933e4cb46f933172a02ca91f41635f8b7bb5c3467b1cf5870de46c22
crc32: 008817C8
md5: 95eeb9a5973bc5af2860a16f93d6cead
sha1: 3a3bc97dd1ab1cc8c9484421a2eba057ceeab378
sha256: f5d10e74933e4cb46f933172a02ca91f41635f8b7bb5c3467b1cf5870de46c22
sha512: edb9de83ec40659a458213ef1152eab7212c5503dacdff95ad4665e22631b31b8b7c8a86ada34ddd25f49c695ba6278cf0020da99cddfc25cf72bb807748ef0f
ssdeep: 12288:JN7qAaluiiivQxUVi9MpvAw642f/2KvWu17u:DOFuofI8K/r+I7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138552832AD8CC83EC96AD538480A925B48F77D70293FDD0E19F48F4C4AB726DEB95152
sha3_384: b1572a800baa68f7c62df1b9b14249f60da07822548ca9553bc3a07927080e487c586142abe09752d58fa2e691c608b6
ep_bytes: 558bec83c4f0b818114500e8304bfbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/GenKryptik.FNWX also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38096886
FireEyeGeneric.mg.95eeb9a5973bc5af
ALYacTrojan.GenericKD.38096886
CylanceUnsafe
K7AntiVirusTrojan ( 0058ac921 )
AlibabaTrojanSpy:Win32/Stealer.a5c49454
K7GWTrojan ( 0058ac921 )
CyrenW32/Kryptik.FVK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNWX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.ajzo
BitDefenderTrojan.GenericKD.38096886
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.10cf8e29
Ad-AwareTrojan.GenericKD.38096886
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.mmyzg@0
DrWebTrojan.Siggen15.50289
ZillyaTrojan.Injuke.Win32.23909
TrendMicroTROJ_FRS.0NA103KP21
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
EmsisoftTrojan.Agent (A)
IkarusTrojan.Win32.Injector
WebrootW32.Trojan.Gen
AviraTR/Kryptik.kezju
MAXmalware (ai score=80)
KingsoftWin32.Troj.Stealer.AJ.(kcloud)
MicrosoftTrojan:Win32/Bunitucrypt.RW!MTB
GDataTrojan.GenericKD.38096886
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.MalwareX-gen.C4786614
McAfeeGenericRXAA-AA!95EEB9A5973B
TACHYONTrojan-Spy/W32.DP-InfoStealer.1288704
VBA32BScope.Exploit.Shellcode
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_FRS.0NA103KP21
RisingTrojan.Generic@ML.92 (RDML:VAl+CJb2IQpLHngRBOI2/w)
YandexTrojanSpy.Stealer!6hVHDIWjJiQ
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.FMWI!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.130260634.susgen

How to remove Win32/GenKryptik.FNWX?

Win32/GenKryptik.FNWX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment