Malware

Win32/GenKryptik.FUIP removal

Malware Removal

The Win32/GenKryptik.FUIP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FUIP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Uzbek (Latin)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/GenKryptik.FUIP?


File Info:

name: 2E9541D956695722168C.mlw
path: /opt/CAPEv2/storage/binaries/1d469dd2bc5c1abcec57484d8afb4c39cf7018950d62f0e63bab1530114a1b02
crc32: 256EF089
md5: 2e9541d956695722168c6898779825b1
sha1: 901555f9bcc97083f7f50676626e1e96abbdb9ec
sha256: 1d469dd2bc5c1abcec57484d8afb4c39cf7018950d62f0e63bab1530114a1b02
sha512: 86d9dc2d08004d2374ebd29e8d81cfe097d2754e8a38b2bb638917e22eaaeab167dc3167ca542f28d9328f815aed888121f5e65ee4e4aee0ab5a0cfecef414c6
ssdeep: 49152:qXtkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkM:q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0C68D407794E955D2582EB6493B8AE25A3AFCDBD91442CB32197F0FFC326406D86F23
sha3_384: 17acdcbecc8d4f9f230c81295de83b72dd8154734b2081c57a444c4d49cacd761d6f2159708622b9ff364cae9d96f23e
ep_bytes: 8bff558bece8c6a70000e8110000005d
timestamp: 2021-09-10 03:27:58

Version Info:

Translations: 0x0203 0x02bd

Win32/GenKryptik.FUIP also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebTrojan.Siggen17.49432
FireEyeGeneric.mg.2e9541d956695722
CAT-QuickHealRansom.Stop.P5
McAfeePacked-GEE!2E9541D95669
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FUIP
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Generic@AI.94 (RDMK:cmRtazp57sPLqgVRpRyK97kT+RBe)
McAfee-GW-EditionBehavesLike.Win32.Worm.wm
SophosML/PE-A
IkarusTrojan-Ransom.StopCrypt
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
APEXMalicious
SentinelOneStatic AI – Malicious PE
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.9bcc97

How to remove Win32/GenKryptik.FUIP?

Win32/GenKryptik.FUIP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment