Malware

How to remove “Win32/GenKryptik.FPVO”?

Malware Removal

The Win32/GenKryptik.FPVO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FPVO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.FPVO?


File Info:

name: 5AA510583281F9BB37BE.mlw
path: /opt/CAPEv2/storage/binaries/9d8f4fbc5942e6de0867353e4b4ab1c7414ef0403747f06aac38717692204ba4
crc32: A90350DA
md5: 5aa510583281f9bb37be6de589cd5721
sha1: 9165c1d56e329b4a17a98c5460c26a7995d70595
sha256: 9d8f4fbc5942e6de0867353e4b4ab1c7414ef0403747f06aac38717692204ba4
sha512: 6c934dcabc6ba347b898afb4c9c9a7def1eb78aa60892f6aa854cd14f6bb9b13ae7347f9dceb0de1a6413c2d308286e290ef2f04f140466fc2ca5079c8d494e6
ssdeep: 6144:UQEQ5V2dk+CGEeNj7I4R257rURjLv89vffDnZQgqY3W94QFDSmie9UFGy3Fte6u3:JEQ5V2Kir7I4YtrURjLvIXfDnZQgdGHJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C8402A8D93414AFCBF5B33FA08ABFE815904F46EA3E67D295C63D518129E52C34C4B4
sha3_384: 60a56609e79a767da6ae4ab10ef3d1c7c81b17343332491ad504b7f1e4158746ff179aa392791b0c74ebb9a0b9e90ab4
ep_bytes: 83ec1cc7042402000000ff1568f24500
timestamp: 2022-02-03 16:22:19

Version Info:

0: [No Data]

Win32/GenKryptik.FPVO also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38881872
McAfeeRDN/Generic.rp
CylanceUnsafe
SangforTrojan.Win32.Khalesi.gen
K7AntiVirusTrojan ( 0058d1841 )
AlibabaTrojan:Win32/GenKryptik.e04ea322
K7GWTrojan ( 0058d1841 )
Cybereasonmalicious.56e329
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FPVO
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Khalesi.gen
BitDefenderTrojan.GenericKD.38881872
AvastWin32:CrypterX-gen [Trj]
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.5aa510583281f9bb
EmsisoftTrojan.GenericKD.38881872 (B)
JiangminTrojan.Khalesi.bfhk
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftPWS:Win32/Zbot!ml
GDataWin32.Trojan-Stealer.TinyNuke.675VOX
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38881872
MalwarebytesTrojan.Injector
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.34182.xGW@ausnxRh
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/GenKryptik.FPVO?

Win32/GenKryptik.FPVO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment