Malware

Win32/Kryptik.FEP removal instruction

Malware Removal

The Win32/Kryptik.FEP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FEP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.FEP?


File Info:

name: 9B44A7ADFB45288338B9.mlw
path: /opt/CAPEv2/storage/binaries/470823d4362b5f1f3687135a1379337ef2a5e8b3d9b76612bfb5b0a45175aaac
crc32: A31F22E5
md5: 9b44a7adfb45288338b96477ad709ab2
sha1: c0784b34dc70eaa10f9c359e3caf01396b9a4d39
sha256: 470823d4362b5f1f3687135a1379337ef2a5e8b3d9b76612bfb5b0a45175aaac
sha512: aa88fcc72938cc37bbb575e8e11e62b3a84c158df71e08c198bf526523b30ce8b9a7a520a87183115ddd44f382844b1e89c49c8d0ccbe1cf5d18d99c99f861a4
ssdeep: 3072:43/lrUQLHxFcxXL5sXTtOyMLgP56dzg7I5nPlVxmIzrcsztLd8snzCHdtMe:43/LLHxCxWXROFm6BDPlzzgULfzCHP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8F3F1629BFE282FE4A3DD3791E4F91EDD0F6C560385E59BD2832D1E012ADF18624325
sha3_384: 175ee092ae24d0d552316a8de0da9ba67da8b0f08fb9746853cba10ebd0171e71baee425773cf5d25ff6524488ed020a
ep_bytes: f7d7e95e0a000021b42c723436da2448
timestamp: 2009-07-22 17:00:06

Version Info:

0: [No Data]

Win32/Kryptik.FEP also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Renos.22
SkyhighBehavesLike.Win32.Ctsinf.ch
McAfeeDownloader-CEW.cp
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000061 )
AlibabaPacked:Win32/Katusha.2cd534dc
K7GWTrojan ( 700000061 )
Cybereasonmalicious.4dc70e
BitDefenderThetaAI:Packer.FDC90A251E
VirITPacked.Win32.Katusha.N
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.FEP
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Katusha.n
BitDefenderGen:Variant.Renos.22
NANO-AntivirusTrojan.Win32.Katusha.bpyiq
AvastWin32:DropperX-gen [Drp]
RisingDownloader.Renos!8.1D0 (TFE:1:7DUFnbB0YGE)
EmsisoftGen:Variant.Renos.22 (B)
F-SecureTrojan.TR/Agent.160264
DrWebTrojan.DownLoad1.64184
VIPREGen:Variant.Renos.22
TrendMicroTROJ_FAKEAV.SMA3
SophosMal/FakeAV-CX
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.ljz
WebrootW32.Malware.gen
VaristW32/FakeAlert.HD.gen!Eldorado
AviraTR/Agent.160264
Antiy-AVLTrojan[Packed]/Win32.Katusha
Kingsoftmalware.kb.a.1000
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.Renos.22
ZoneAlarmPacked.Win32.Katusha.n
GDataGen:Variant.Renos.22
GoogleDetected
AhnLab-V3Trojan/Win32.Katusha.R48103
VBA32BScope.Trojan.Downloader
PandaTrj/Katusha.M
TrendMicro-HouseCallTROJ_FAKEAV.SMA3
TencentMalware.Win32.Gencirc.116c13a3
YandexTrojan.Kryptik!WXjgY4xurxg
IkarusTrojan.Cryptic
MaxSecureTrojan.Malware.7175850.susgen
FortinetW32/CodePack.CX!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.FEP?

Win32/Kryptik.FEP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment