Malware

Win32/GenKryptik.FZCY removal

Malware Removal

The Win32/GenKryptik.FZCY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FZCY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/GenKryptik.FZCY?


File Info:

name: 283BF6262F4D1BFF8C02.mlw
path: /opt/CAPEv2/storage/binaries/753737472c8d2ff40f7836170279e3039dda162ea1cfeeb0eb7ef6349fb759c9
crc32: C1CA054F
md5: 283bf6262f4d1bff8c028e01ec6d69d3
sha1: 6c7cf877786432cc5edc6b0c2df9a71c1b101d6e
sha256: 753737472c8d2ff40f7836170279e3039dda162ea1cfeeb0eb7ef6349fb759c9
sha512: f2b02400bb9092faa1c9816970e4ea45c240682391ae1f5e3f102779fdbb5c1afafb3accac1aaccdaf040840f1de8ebfc19908e42c2c3e1f434094dd5541ff33
ssdeep: 6144:VPsOzg3c8OlC93so886NPto89LTyzlJKlLynbu7oCpoU/PuO9:lsDc8OlC93tUKsHMK1DoCpBP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18684BF40BA60C03DF4B721F4B9B6C2BC692A7EA1672055CB62D637EE56346D0EC74387
sha3_384: 68ef825a378c97544b12a0e4db91f3fce6bf4c6206e1cf5cc6b042ea88efeb7215fff8ef56f1b2f657894a0ad9ec988c
ep_bytes: 8bff558bece806750000e8110000005d
timestamp: 2021-08-26 07:19:44

Version Info:

Translations: 0x0283 0x00aa

Win32/GenKryptik.FZCY also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
FireEyeGeneric.mg.283bf6262f4d1bff
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058e4621 )
K7GWTrojan ( 0058e4621 )
Cybereasonmalicious.778643
CyrenW32/Kryptik.HIO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FZCY
APEXMalicious
KasperskyHEUR:Trojan.Win32.Injuke.gen
AvastWin32:PWSX-gen [Trj]
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.H1TZNQ
CynetMalicious (score: 100)
McAfeePacked-GEE!283BF6262F4D
VBA32BScope.TrojanDownloader.Smoke
MalwarebytesMalware.AI.2665744179
RisingTrojan.Convagent!8.12323 (TFE:5:1bxZXKER0SJ)
IkarusTrojan-Ransom.StopCrypt
FortinetW32/Kryptik.HHPX!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/GenKryptik.FZCY?

Win32/GenKryptik.FZCY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment