Malware

Win32/GenKryptik.FTVU (file analysis)

Malware Removal

The Win32/GenKryptik.FTVU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FTVU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FTVU?


File Info:

name: 1C85011F7A874B5A2F39.mlw
path: /opt/CAPEv2/storage/binaries/49c7503285415c1b4793529ca2440f8052546f437d3674daa7fd1964c29c3fe0
crc32: 4FC3B183
md5: 1c85011f7a874b5a2f39c08c6cf978d5
sha1: 63d73536a4ea6d64c9b50e46275cc46fe82e71d7
sha256: 49c7503285415c1b4793529ca2440f8052546f437d3674daa7fd1964c29c3fe0
sha512: 1335e3eb4026a4a1fc421b16d20abfe190c9d72e49e486f3946f6d559b7f981cbc57b207406cc5dfb5f376b942dfd8de3926352a69975207cc3d8f95cbf55989
ssdeep: 12288:PZzbQm7i/aAjSBE9SiBkQEh71bJE6TdPXNJDNm8Pbt5bjmlco7jni9KiibggGPXB:P1Em+/JSBGAQkw2fr88Dt5bSlcW7oT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178556C31E1A058F6D4620E758E169259FEA6BD103E14DD4EE6B43DEC2E37780E8142FB
sha3_384: 4444be795379b1e0ed9a2b7fd5c1e5cded2c67c4c6f7ad863bf823b702b698b1c891e206825a48ee84376ab83f79d755
ep_bytes: 558bec83c4f0535657b8a8364c00e881
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription: Resource viewer, decompiler & recompiler.
FileVersion: 3.4.0.79
InternalName: ResHack
LegalCopyright: (c) Angus Johnson 1999-2002
LegalTrademarks:
OriginalFilename: ResHack
ProductName:
ProductVersion: 3.0.0.0
Comments: Freeware, but see help file for conditions.
Aditional Notes: Not for distribution without the authors permission
Translation: 0x0c09 0x04e4

Win32/GenKryptik.FTVU also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Autoruns.GenericKDS.50208605
FireEyeTrojan.Autoruns.GenericKDS.50208605
ArcabitTrojan.Babar.DABD7
CyrenW32/Injector.PQSU-0406
SymantecScr.MalPbs!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FTVU
APEXMalicious
KasperskyVHO:Backdoor.Win32.Agent.gen
BitDefenderTrojan.Autoruns.GenericKDS.50208605
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.Autoruns.GenericKDS.50208605
EmsisoftTrojan.Autoruns.GenericKDS.50208605 (B)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.Autoruns.GenericKDS.50208605
AhnLab-V3Malware/Win.Generic.C5104219
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Limpopo
RisingTrojan.Hesv!8.EDB6 (TFE:dGZlOgVIW5VkIf17ag)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EQPQ!tr
BitDefenderThetaGen:NN.ZelphiF.34606.oH1@aaX7Rkek
AVGWin32:MalwareX-gen [Trj]

How to remove Win32/GenKryptik.FTVU?

Win32/GenKryptik.FTVU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment