Malware

How to remove “Win32/GenKryptik.FWOS”?

Malware Removal

The Win32/GenKryptik.FWOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FWOS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.FWOS?


File Info:

name: E94AC1E69895AF8AF542.mlw
path: /opt/CAPEv2/storage/binaries/8c5476f3ca1b703e2ab8f2dd9a88bd782401a1ae3e9f9273ca5e144ade318c55
crc32: A4F7320C
md5: e94ac1e69895af8af5426aebe96a565e
sha1: 2fe08970825763ddc185dd5421f3ac096bdcb7cb
sha256: 8c5476f3ca1b703e2ab8f2dd9a88bd782401a1ae3e9f9273ca5e144ade318c55
sha512: b6cdb729467fa629f7c33ee7143e8730a38c3e17ec7df0a611aa99c5460f8ca1b2fdc3202c720206054c02a1f42d784e8db0aa6c0a066db4666f773ef3d7c4d0
ssdeep: 6144:1MyykUMA520eyTrwFIIK7gxreqdAOQVvNCiKJcVNnUKmM:WJLMA57eyHpqdGKJcV1m
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A7848D00F691803AFC7319334E79BA9D6D2CA9130B5517DBFB9C9EADCE644E07A30616
sha3_384: 07031eae6877e9ba08c9d8a560a8639a493099b6234cb329ef3f1ffbf96a39c0db45f820646ba3b42e3700c444713e76
ep_bytes: e88b080000e974feffff8b4df464890d
timestamp: 2022-06-24 16:45:08

Version Info:

0: [No Data]

Win32/GenKryptik.FWOS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.PWS.Steam.28157
MicroWorld-eScanGen:Variant.Lazy.201445
FireEyeGeneric.mg.e94ac1e69895af8a
McAfeeGenericRXTL-DV!E94AC1E69895
CylanceUnsafe
SangforTrojan.Win32.Agent.Vnvi
AlibabaTrojanSpy:Win32/Stealer.527c5544
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.34742.yqW@amr8Zho
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FWOS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.201445
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@AI.87 (RDML:w0K5izy/bEZvvfe6ARcpPg)
Ad-AwareGen:Variant.Lazy.201445
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.FileTour.fh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.201445 (B)
GDataGen:Variant.Lazy.201445
AviraTR/AD.Nekark.ajxtt
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5180391
VBA32BScope.Trojan.Zapchast
ALYacGen:Variant.Lazy.201445
MalwarebytesSpyware.PasswordStealer
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HPXZ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Win32/GenKryptik.FWOS?

Win32/GenKryptik.FWOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment