Malware

About “Win32/Kryptik.FGGS” infection

Malware Removal

The Win32/Kryptik.FGGS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FGGS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • Anomalous binary characteristics

How to determine Win32/Kryptik.FGGS?


File Info:

crc32: 2EE71036
md5: b2fecafbc2a2f07dc3fea903d0336deb
name: B2FECAFBC2A2F07DC3FEA903D0336DEB.mlw
sha1: d4bc7ea0c539ff98646bd5cd25b5bfb4357cdb5f
sha256: 9edf3a9e168dee371848a7e69b9f3e652c5320d70047e6514f81cf1eb69852cc
sha512: 6d7cedabfa6690a993393986ffe74d8c1dcb35f1ed1dabd93e7e96f9e740ac5006794d4ad157b00ad5be0a439ce381744f2a751aabda6d0b3bf76a9c36329803
ssdeep: 3072:vK6xK74pmISZAP8syVwi08NZqPnWmqf0NJTzYb4h2zpW8fJGy5T851JqG:s4pBP8sFTuqPnPgGkbjzpHf4yQx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.FGGS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004fa86d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealTrojanRansom.Crowti.MUE.A4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004fa86d1 )
Cybereasonmalicious.bc2a2f
BaiduWin32.Trojan.Cerber.h
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FGGS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fnlp
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Zerber.evpnym
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Raasc.Auto
Ad-AwareTrojan.Ransom.Cerber.1
SophosMal/Generic-R + Mal/Cerber-K
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaAI:Packer.BD58FB7A1E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM30
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.b2fecafbc2a2f07d
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.dih
AviraHEUR/AGEN.1106603
eGambitUnsafe.AI_Score_67%
MicrosoftTrojan:Win32/Dorv.D!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeGenericRXDH-PV!B2FECAFBC2A2
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesMalware.AI.3377204730
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM30
RisingRansom.Cerber!8.3058 (CLOUD)
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.HEKH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.FGGS?

Win32/Kryptik.FGGS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment