Malware

Win32/GenKryptik.FZQD (file analysis)

Malware Removal

The Win32/GenKryptik.FZQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.FZQD virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.FZQD?


File Info:

name: CF89D0FDB1BBB1D57053.mlw
path: /opt/CAPEv2/storage/binaries/c0a4229448a9916275fccf9bed9537817ff1a9908d463a2541b014664f7ec21a
crc32: 5DD6F22F
md5: cf89d0fdb1bbb1d57053dd215b6904f9
sha1: 9e1d72dbf7269133b6eb627a8c0565eebb692fc8
sha256: c0a4229448a9916275fccf9bed9537817ff1a9908d463a2541b014664f7ec21a
sha512: 6253f65c0bb05e79842647bd07a9af4e09f83173f001d15d7d4413a4b434a8d9df1fd9cce5684eedd33ef2fca1cff49a8a85abbfada2f5241fea352bed419732
ssdeep: 3072:N1lYxWpd54BaHhqA0UXEfhEYbzPCTVZR3AWijGn4p:3eH7XUU5EYCTvaBjR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124649E0B77F20653E7AB5B39A5B6C2A5E273BD241F23455B2140352E3D32E814E26B93
sha3_384: ad48f36228de2d91622a66fcec47504e499e0ceb17dd46747f708f55f8ac73ffaf7e64685082c12462d3ac6dfd7aaa0a
ep_bytes: 680c3a4000e8f0ffffff000000000000
timestamp: 1970-01-01 00:00:00

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: File Folder
OriginalFilename: File Folder.exe

Win32/GenKryptik.FZQD also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.sm0@sr3!K7cib
FireEyeGeneric.mg.cf89d0fdb1bbb1d5
CAT-QuickHealTrojan.VBCrypt.MF.233
ALYacGen:Trojan.Heur.sm0@sr3!K7cib
MalwarebytesMalware.AI.3487950891
ZillyaWorm.VB.Win32.45590
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
BitDefenderGen:Trojan.Heur.sm0@sr3!K7cib
K7GWTrojan ( 005640b91 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.DE1E8A3E1D
VirITTrojan.Win32.VB_Heur
CyrenW32/Backdoor.J.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.FZQD
BaiduWin32.Worm.VB.a
APEXMalicious
ClamAVWin.Worm.VB-663
KasperskyEmail-Worm.Win32.VB.cp
CynetMalicious (score: 100)
RisingWorm.VB.aea (CLASSIC)
Ad-AwareGen:Trojan.Heur.sm0@sr3!K7cib
SophosML/PE-A + W32/MoonLig-J
ComodoWorm.Win32.VB.~F@go7q
F-SecureWorm.WORM/Lightmoon.X
DrWebWin32.HLLW.Vugung
VIPREGen:Trojan.Heur.sm0@sr3!K7cib
TrendMicroWORM_LIGHTMOON.Z
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ft
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.sm0@sr3!K7cib (B)
IkarusWorm.Win32.Lightmoon
JiangminI-Worm/VB.g
AviraWORM/Lightmoon.X
Antiy-AVLTrojan/Generic.ASMalwS.54C8
MicrosoftWorm:Win32/Lightmoon.H
ZoneAlarmEmail-Worm.Win32.VB.cp
GDataWin32.Worm.LightMoon.A
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
McAfeeW32/MoonLight.worm.b
MAXmalware (ai score=81)
PandaW32/Moonlight.T.worm
TrendMicro-HouseCallWORM_LIGHTMOON.Z
TencentWorm.Win32.VB.aac
YandexI-Worm.Moonlight.C
SentinelOneStatic AI – Malicious PE
FortinetW32/MoonLight.B!tr
AVGWin32:Malware-gen
Cybereasonmalicious.db1bbb
AvastWin32:Malware-gen

How to remove Win32/GenKryptik.FZQD?

Win32/GenKryptik.FZQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment