Malware

What is “Troj/Krypt-FD”?

Malware Removal

The Troj/Krypt-FD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Krypt-FD virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Troj/Krypt-FD?


File Info:

name: 3B9921647926C113BD32.mlw
path: /opt/CAPEv2/storage/binaries/3e8ea4cf0d87dbd179ffb52af44b6b5e02c54f2f465b0a861f0ffc90ebcf0c70
crc32: A874B3A9
md5: 3b9921647926c113bd32c5ba26913dbf
sha1: 3f4747bb6f0a9c44cee896ed4888a94c54a76f5e
sha256: 3e8ea4cf0d87dbd179ffb52af44b6b5e02c54f2f465b0a861f0ffc90ebcf0c70
sha512: 89dbe70ce1b9d92e3f2fa6b01b9c737998f1fd2ad0ad57d54717763e73af5651b3a32c1d048e676e1c2c617c93b60798ae1fdfd6ca8f3c0d967f9fb3adff5780
ssdeep: 12288:+nGPk0eixBFmk4X9TQFenF7wTW2jCXiD4dAzMtpf+1KKKfO:+nUk0ei1DA+enF7iW2jCycd7v+8KKW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E940115537C5214CEAD8F7BA0E58241533FE626F94ADB0A37C1A46C19E63036B227EF
sha3_384: 94ebe76c00634fb62345e3fcb2017070e637176f31c32c136fbd8c586d5897ba55cfc3ec309f01d6cba4370f4dea24a6
ep_bytes: ff250020400036000000ad0e00000800
timestamp: 2021-11-25 08:26:54

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Rogers Peet
FileDescription: Biblan
FileVersion: 5.6.0.0
InternalName: StackEnumerat.exe
LegalCopyright: Copyright © Rogers Peet
LegalTrademarks:
OriginalFilename: StackEnumerat.exe
ProductName: Biblan
ProductVersion: 5.6.0.0
Assembly Version: 8.0.6.0

Troj/Krypt-FD also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.53056
MicroWorld-eScanTrojan.GenericKD.38117270
FireEyeGeneric.mg.3b9921647926c113
ALYacTrojan.GenericKD.38117270
K7AntiVirusTrojan ( 0058ae7c1 )
CyrenW32/MSIL_Kryptik.GEB.gen!Eldorado
SymantecScr.Malcode!gdn30
ESET-NOD32a variant of MSIL/Kryptik.ADOI
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.38117270
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38117270
SophosTroj/Krypt-FD
McAfee-GW-EditionBehavesLike.Win32.Fareit.gc
EmsisoftTrojan.GenericKD.38117270 (B)
IkarusTrojan.MSIL.Inject
GDataTrojan.GenericKD.38117270
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4789033
MalwarebytesTrojan.Crypt.MSIL
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetMSIL/GenKryptik.FOAM!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/Krypt-FD?

Troj/Krypt-FD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment