Malware

How to remove “Win32/GenKryptik.FZBA”?

Malware Removal

The Win32/GenKryptik.FZBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FZBA virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FZBA?


File Info:

name: 92A0CB724647896316D8.mlw
path: /opt/CAPEv2/storage/binaries/893253226a03c86822b4130e92ecc694317d37388e2578c3a919b0ff96e9491d
crc32: B4C1BF5E
md5: 92a0cb724647896316d8610ccc12e890
sha1: 76651a13611541f26e052a6d4fa6893b2890f699
sha256: 893253226a03c86822b4130e92ecc694317d37388e2578c3a919b0ff96e9491d
sha512: 9c841ae8c5b6b752ba65fa02f0b7e13e82b930ff469d49ef5730dbd246e2095c23a19b0a205c0a84ea7ce6ec7cc15fcab689b74589bc81bebfa73c24ff433877
ssdeep: 1536:YSofeF/b4KstJBGw9/YgKi4QyE7JxTBcu6wLhj:Ycb41tJBGIfHVTBcu6wLh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB83BF17A0119945DB3545B2198ACD38BDAABEFF6FE0C70F29E17C4777B21827021163
sha3_384: 437f3669d80818cc88f05ba49be976fd37582a015fbb6b9bc4f100796001f3a53dc4cad72e89ec76aa166edc1371f4e6
ep_bytes: e853000000e830010000a124f0510333
timestamp: 2003-12-05 23:47:12

Version Info:

CompanyName: Valve
FileDescription: Half-Life Launcher
FileVersion: 1, 1, 1, 1
InternalName: Half-Life Launcher
LegalCopyright: Copyright (c) 1996-2003
LegalTrademarks:
OriginalFilename: hl.exe
ProductName: Half-Life Launcher
ProductVersion: 1, 1, 1, 1
Translation: 0x0409 0x04b0

Win32/GenKryptik.FZBA also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Copidmbe.n!c
MicroWorld-eScanGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
FireEyeGeneric.mg.92a0cb7246478963
ALYacGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
CylanceUnsafe
VIPREGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
SangforTrojan.Win32.Agent.Vj5q
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/GenKryptik.cdb046c5
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.246478
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FZBA
ZonerProbably Heur.ExeHeaderL
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Malware-gen
Ad-AwareGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
EmsisoftGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi (B)
TrendMicroTROJ_GEN.R002C0PHG22
McAfee-GW-EditionBehavesLike.Win32.Infected.mh
Trapminemalicious.moderate.ml.score
SophosMal/ZAccess-BL
SentinelOneStatic AI – Malicious PE
GDataGen:Malware.Heur.1.!copidmbe!.fu0@buISd0mi
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitGen:Malware.Heur.1.!copidmbe!.EA5773
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeRDN/Real Protect-LS
VBA32BScope.Trojan.Sheljector
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0PHG22
RisingTrojan.Generic@AI.86 (RDML:2splS7jj6LNmzbLIw+T7qw)
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/GenKryptik.FZBA?

Win32/GenKryptik.FZBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment