Malware

Win32/GenKryptik.FQLF removal tips

Malware Removal

The Win32/GenKryptik.FQLF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FQLF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/GenKryptik.FQLF?


File Info:

name: 5026182814B85CF5371A.mlw
path: /opt/CAPEv2/storage/binaries/0b96758a3126130702cb93d24d1f906e7fda90b30cbe2df4b8cb9b2e65229022
crc32: A2634588
md5: 5026182814b85cf5371af0eef47c250d
sha1: 9817d2bb8b91a2b9333c403e6ba180ee38283234
sha256: 0b96758a3126130702cb93d24d1f906e7fda90b30cbe2df4b8cb9b2e65229022
sha512: ca5620ce732ee2466b5be330ae6390f74ad1d249c09e6ab5c3e3ebc128151536f0bc13c683b5e7ecbb36938535dbf3727c5e82f8a3ef365bc69efe804ebdefcd
ssdeep: 6144:4yOU+4hywZkuZ6e/OnD6mOfaWKkiAPFqBRfs10RSNDKoH:5jPEwi6bWnD6mOb0APFIRfsTD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143649E10BA90C035F2B756F8467A936CB53E7EA19B2460CB53D52BEE1634AE1EC31317
sha3_384: 3dd87fe97b17f5faf670b733ca1a374606b53e42578b7f0e01c461a4f9b0e2610103b023146a7550e4118b4abadcc774
ep_bytes: 8bff558bece886d60000e8110000005d
timestamp: 2021-02-08 16:38:12

Version Info:

0: [No Data]

Win32/GenKryptik.FQLF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.39411
CynetMalicious (score: 100)
FireEyeGeneric.mg.5026182814b85cf5
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.b8b91a
CyrenW32/Kryptik.GAL.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenKryptik.FQLF
APEXMalicious
ClamAVWin.Malware.Dropperx-9938227-0
KasperskyUDS:Backdoor.Win32.Mokes.gen
AvastWin32:DropperX-gen [Drp]
BaiduWin32.Trojan.Kryptik.jm
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosML/PE-A
IkarusTrojan-Ransom.StopCrypt
MicrosoftTrojan:Win32/Krypter.AA!MTB
ZoneAlarmUDS:Backdoor.Win32.Mokes.gen
McAfeePacked-GEE!5026182814B8
MalwarebytesTrojan.MalPack.GS
RisingMalware.Heuristic!ET#86% (RDMK:cmRtazrDGJ+aIx7L1UQXCYfYmMVA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/GenKryptik.FQLF?

Win32/GenKryptik.FQLF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment