Malware

Win32/GenKryptik.FPJO removal

Malware Removal

The Win32/GenKryptik.FPJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FPJO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.FPJO?


File Info:

name: AF257724CA8DA3BEE630.mlw
path: /opt/CAPEv2/storage/binaries/330d1d4448550b596da4b96f67eae95c591fb6e30a71d9124154799b74b01a8c
crc32: 292C0763
md5: af257724ca8da3bee63077f939f78a68
sha1: c6ac4d737c35ce1dae0d148ac13e8127fd0af1ed
sha256: 330d1d4448550b596da4b96f67eae95c591fb6e30a71d9124154799b74b01a8c
sha512: fcfdf7eae66fc0d4add00c9107477442dfb0a1870628909f0d82cd49984d56f6a0bf4adf3e0771bc9124d48b2f780b01a249fa12993e9059919462c1f4d1db94
ssdeep: 12288:WcurokFX/NYpdlwXW8dBZSbE+VHl/LBQa+m1tCE/4RgrDae5:WcCoMPgqBUJVF/l1Vjrue5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1536502166392E476C1C31671C656F3B01A2E6B31169ED107A71087267E713E2FB2FACB
sha3_384: 14d7abdf6baa219b63b4bbf5223652f2f2a2ae75e0e9883e6361129456879d5b99d71e8475690080cc97568dbb410b4e
ep_bytes: e88d250000e978feffff3b0d1410022e
timestamp: 2010-01-10 04:16:28

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Office Source Engine
FileVersion: 14.0.4730.1010
InternalName: ose
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: ose.exe
ProductName: Office Source Engine
ProductVersion: 14.0.4730.1010
Translation: 0x0000 0x04e4

Win32/GenKryptik.FPJO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Oficla.10
FireEyeGeneric.mg.af257724ca8da3be
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderGen:Variant.Oficla.10
K7GWTrojan ( 0058c7021 )
K7AntiVirusTrojan ( 0058c7021 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FPJO
TrendMicro-HouseCallTROJ_GEN.R002C0WA122
KasperskyUDS:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
Ad-AwareGen:Variant.Oficla.10
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WA122
McAfee-GW-EditionBehavesLike.Win32.Virutrem.tt
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Oficla.10 (B)
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Oficla.10
AhnLab-V3Malware/Win.FileInfector.R462020
McAfeeArtemis!AF257724CA8D
MAXmalware (ai score=89)
VBA32BScope.Trojan.Convagent
MalwarebytesMalware.AI.1638163793
TencentWin32.Trojan.Oficla.Lnxt
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_92%
FortinetW32/Expiro.NDO!tr
AVGFileRepMalware
Cybereasonmalicious.4ca8da
AvastFileRepMalware

How to remove Win32/GenKryptik.FPJO?

Win32/GenKryptik.FPJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment