Malware

Win32/Kryptik.FDT malicious file

Malware Removal

The Win32/Kryptik.FDT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FDT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Win32/Kryptik.FDT?


File Info:

name: 06D445682E60D46B3BE4.mlw
path: /opt/CAPEv2/storage/binaries/46d350b1edd87503723554e7aa57086a4714e282fa8556fef826edee42190dc2
crc32: BAC0D730
md5: 06d445682e60d46b3be44642c0a23b03
sha1: c718a630310effc6005225e6cb30cef0c9604425
sha256: 46d350b1edd87503723554e7aa57086a4714e282fa8556fef826edee42190dc2
sha512: 34e43d4e820802c8bc1f704a78835474794d2080d9f92da9d77db6399c654a195a578696070c94efb311184f1524f7b787f4ed8793584cf759bab90e8cc6256a
ssdeep: 3072:tGFJlcBqGbwEoAdmplJpppnAK7QWqVZ0NdhAPSwz/LPKTAuLF:cFJlcBqOklJppJl7uVZ0NdhAJpEF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16004BF44E6F4C111D533ABFC6EB88D0319AC1BB225FBC8D98C2D735886491F781A66ED
sha3_384: 0e1b8123e56cd4a13f47b59e623d377e6b710bd252001f4893f8eb72dd8ac129c3bfaba39b7533c6cb50bdf589757461
ep_bytes: 558bec81c498feffff6a69ff75b48d95
timestamp: 2006-01-24 13:31:17

Version Info:

CompanyName: ОФнбзщЫУшВНШэрзюЫзОюхюлОжЬъЧ
FileDescription: ГкфЧючнЗЪнСсббЦюхЫепАП
FileVersion: 54.119.92.8
InternalName: шНшЫяИБКЮХИьмчлрЮьЬАВЯУЫяЛ
LegalCopyright: 9767-5092
OriginalFilename: 3Jl.exe
ProductName: йЖЕдЖчныБивОэршЭГяВхшЮЕ
ProductVersion: 54.119.92.8
Translation: 0x04b0 0x0417

Win32/Kryptik.FDT also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Oficla.3
FireEyeGeneric.mg.06d445682e60d46b
CAT-QuickHealTrojan.GenericPMF.S19414889
ALYacGen:Variant.Oficla.3
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.881841
SangforTrojan.Win32.Kryptik.FDT
K7AntiVirusTrojan ( 0017c0111 )
AlibabaTrojanPSW:Win32/Kryptik.7eba5aca
K7GWTrojan ( 0017c0111 )
Cybereasonmalicious.82e60d
BitDefenderThetaAI:Packer.9A69023E1F
VirITTrojan.Win32.Generic.CST
CyrenW32/Zbot.AK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.FDT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Oficla.3
NANO-AntivirusTrojan.Win32.Zbot.ddance
AvastWin32:MalOb-IJ [Cryp]
TencentMalware.Win32.Gencirc.10b6295c
Ad-AwareGen:Variant.Oficla.3
SophosMal/Generic-R + Mal/Zbot-U
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Packed.20343
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionGenericRXHD-SA!06D445682E60
EmsisoftGen:Variant.Oficla.3 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Oficla.3
JiangminTrojanSpy.Zbot.aifc
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18124F6
ViRobotTrojan.Win32.A.Zbot.150596
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Qakbot.C1477988
Acronissuspicious
McAfeeGenericRXHD-SA!06D445682E60
VBA32BScope.Trojan.Packed
TrendMicro-HouseCallBKDR_QAKBOT.SMC
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojanSpy.ZBot.Gen!Pac.14
SentinelOneStatic AI – Malicious PE
eGambitGeneric.PSW
FortinetW32/Krypt.A!tr.dldr
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Kryptik.FDT?

Win32/Kryptik.FDT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment