Malware

What is “Win32/GenKryptik.FZIT”?

Malware Removal

The Win32/GenKryptik.FZIT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FZIT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Kannada
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/GenKryptik.FZIT?


File Info:

name: 7ED5FEFF69DE0B4009CA.mlw
path: /opt/CAPEv2/storage/binaries/7e6d63066a8d613ad7aaf41c5145ea02bbec51c6fa8ab297500ea7eaf71a534d
crc32: 73D049F7
md5: 7ed5feff69de0b4009caffc0e1e9c046
sha1: 7dbbeb84f3972e510e1326b975806b5fd6cb0139
sha256: 7e6d63066a8d613ad7aaf41c5145ea02bbec51c6fa8ab297500ea7eaf71a534d
sha512: 90f6f3aeae385baf3a89874e6693e338b1da79908b48fda2c88f5e43b3ad29019fb6d2476221602e588f6ecfa6e946197eb62393cd3c65dec1c5fe8f3a351112
ssdeep: 3072:rhrX64xnnQ/OzqXhh77RxDxkh63nQYsxkgaBChgpZa9uD6Vdyhkf:BX1xn2hhfjDxqCnQFigaLwVf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D04BF027EE34975F2626E30586597A1533BBF52AA33604BF754A31F1EB33904AB1327
sha3_384: 9915b790d22ac9ad96a36b7a9026add599d9818f3f88f21b3c85e0411f6d463217d56e430cfafb3f6c7765b76dcf2df6
ep_bytes: e88b200000e989feffff2da403000074
timestamp: 2021-08-31 23:11:11

Version Info:

FileVersions: 98.55.22.41
Copyright: Copyright (C) 2022, soboklos
ProjectVersion: 74.85.66.75

Win32/GenKryptik.FZIT also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.7ed5feff69de0b40
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.4f3972
CyrenW32/Kryptik.HGS.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.FZIT
KasperskyVHO:Trojan.Win32.Convagent.gen
CynetMalicious (score: 100)
AvastCrypterX-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:c+Eyc20Lc8majQAjezkMIA)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosML/PE-A
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
MalwarebytesTrojan.MalPack.GS
IkarusTrojan.Win32.Ranumbot
AVGCrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/GenKryptik.FZIT?

Win32/GenKryptik.FZIT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment