Malware

Should I remove “Win32/GenKryptik.FZNH”?

Malware Removal

The Win32/GenKryptik.FZNH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FZNH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Azeri
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RaccoonV2 malware family
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Win32/GenKryptik.FZNH?


File Info:

name: 138097F13DA831D5E697.mlw
path: /opt/CAPEv2/storage/binaries/77c586fc91e1a030ea6a9181c8ccf99798c7d39bb4facfbb91bf130ab2b48432
crc32: 62CFBC5B
md5: 138097f13da831d5e6971746c836144c
sha1: 5032dc6c23c4b44abfbdc0752f90e94c0fd7739b
sha256: 77c586fc91e1a030ea6a9181c8ccf99798c7d39bb4facfbb91bf130ab2b48432
sha512: 696633a6c6db6ab6f3a30fe7a726f6cbc4a61ecfcf6e4e02f1ca3b7d841e3b724cb9a72ab0ddfb7ccefb6804339c2644bddf32f37b56dd88a2659cb1f3520e66
ssdeep: 12288:N/1tTk46QbqKYT7PCsj9wptoOgIBbh5MpUAvRfJc0dT+k9h23XBDjiPA7G:N9xn628P9j0WOgIJh5M9JcKKk9JPA7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190F46C22B2F58733C2721A7D8D7B5378982ABE113D38A94A3BF50D8C4E3964175353A7
sha3_384: 432d66fc6209d86f628e62877d9222203699a4cc4f64ae930d6b19ca5ef71f3f4b45bb5225026fa9ae2ae27d76609a67
ep_bytes: 558bec83c4f0b834e04800e81080f7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/GenKryptik.FZNH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.91415
FireEyeTrojan.GenericKDZ.91415
ALYacTrojan.GenericKDZ.91415
CylanceUnsafe
K7AntiVirusTrojan ( 005955151 )
AlibabaTrojanSpy:Win32/Stealer.db13743a
K7GWTrojan ( 005955151 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FZNH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKDZ.91415
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKDZ.91415
EmsisoftTrojan.GenericKDZ.91415 (B)
DrWebTrojan.PWS.Siggen3.21710
McAfee-GW-EditionBehavesLike.Win32.BadFile.bh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Stealer.Racealer.EMVCIC
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5230564
McAfeeGenericRXAA-AA!138097F13DA8
VBA32Malware-Cryptor.Limpopo
MalwarebytesMalware.AI.4189244368
RisingStealer.Agent!8.C2 (TFE:5:s2yGAp54BiK)
IkarusBackdoor.QBot
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen

How to remove Win32/GenKryptik.FZNH?

Win32/GenKryptik.FZNH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment