Malware

Win32/Kryptik.FECC removal guide

Malware Removal

The Win32/Kryptik.FECC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FECC virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.FECC?


File Info:

crc32: 21ED1FE0
md5: b787dd91d9739954ebec07e68a978c33
name: B787DD91D9739954EBEC07E68A978C33.mlw
sha1: 23df419aea739726d5c1aa116aea3d6236235a8c
sha256: 3936dbee155a75ea19b638e2a7077f315e05f0bfb976c39d6e701c6cdace4da5
sha512: 7e2021c20a59555eb972901fbde21e0d5ca3d0c9b988e2457b66ad20286fd1c9921788e64c0a862dd4dedaf7c143b55c349d2cd489b3a42522d020baee91e9d0
ssdeep: 6144:l9Bvm4D6oSKZyZu3kv9FIYTSVlMXD3Nk8U6WV5K/:N/67KUZIkvTMVlMXDdXs2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zFM
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.FECC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5189
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.YY2
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Cerber.Win32.519
SangforRansom.Win32.Cerber_65.se
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.8b2f5a08
K7GWTrojan ( 005224381 )
Cybereasonmalicious.1d9739
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FECC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-7067571-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Encoder.evrdsp
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Pgct
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Cerber-K
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaAI:Packer.84C0A1DA20
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM2
McAfee-GW-EditionBehavesLike.Win32.Ransomware.fh
FireEyeGeneric.mg.b787dd91d9739954
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117922
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Packed.Win32.Mentiger.gen
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-FOS!B787DD91D973
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Win32.Vals.6
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM2
RisingTrojan.Kryptik!1.AF0E (CLASSIC)
YandexTrojan.GenAsa!TFMdDooNg7M
IkarusTrojan.Crypt
FortinetW32/Kryptik.HJJV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBG08A

How to remove Win32/Kryptik.FECC?

Win32/Kryptik.FECC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment