Malware

About “Win32/GenKryptik.FWWJ” infection

Malware Removal

The Win32/GenKryptik.FWWJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FWWJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • CAPE detected the PyInstaller malware family

How to determine Win32/GenKryptik.FWWJ?


File Info:

name: 708BB53B08B0063A802D.mlw
path: /opt/CAPEv2/storage/binaries/06ad15b9a73f36e7e20479da20934e8f23b4d7973b1bf2f3af8280069bb2a67b
crc32: 9B7BA49F
md5: 708bb53b08b0063a802d4e0fa55275a6
sha1: 96fc1b1dc53703613878d295f0bd5990434e7f3d
sha256: 06ad15b9a73f36e7e20479da20934e8f23b4d7973b1bf2f3af8280069bb2a67b
sha512: 5769fa4e08d565e7b65f901ed4f50f72a7e775c67308a0fee350f6f94dd88fd32efa649814da77b833602e5c4e3c98f726a7ca80f0756ed90b4304e36f419739
ssdeep: 98304:1nFXjOqOvYvugUYGQFTd1cR5Oh7IRTr/T5jIAXGJ9C00ICGg9YVMMd/MemKqTyqG:lp6vvtYFDcR5Oh7cT2+meSHKexqh
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13666333322691145E1E6CC39C93BFD91B1FB475A4B80ECBD51EBADC235224E5E212E63
sha3_384: 2e58c783e78ac22ddbe783fb35e5880abb16b0a21e8c7e1417f5688d731365389772e00bfc26ca6b39538d53a792b482
ep_bytes: e8c4c64100668b4c25006623d7668b55
timestamp: 2018-09-04 14:42:13

Version Info:

0: [No Data]

Win32/GenKryptik.FWWJ also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
FireEyeGeneric.mg.708bb53b08b0063a
CylanceUnsafe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FWWJ
APEXMalicious
CynetMalicious (score: 100)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZexaF.34786.@NW@aqyq7Wf
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Generic@AI.90 (RDML:H96+tIsTkHYbv27CmaxGjQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/GenKryptik.FWWJ?

Win32/GenKryptik.FWWJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment