Malware

Win32/Kryptik.FJND removal

Malware Removal

The Win32/Kryptik.FJND is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FJND virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.FJND?


File Info:

crc32: AFEF6293
md5: b8c3daaf21fa2ac626450dd78749db2b
name: B8C3DAAF21FA2AC626450DD78749DB2B.mlw
sha1: 464f0a3a225d13fd826a16ddf8c0f715198d23a5
sha256: ad4542d6faf1c26c78eeb6784b71e348d8cb3139e2a25f21678eea440e99883d
sha512: 460b29b5922137d2c9c3b73f72514ed54a4ad97f2976776c27ceabf91d842bc666fb2bb8337821f3050ddb2db2590b70b63da38d65cd0c7e2015d2b0c009f2ff
ssdeep: 12288:gxTG5Vc1lc+zIW+y+s6j/glaj/Y1NgHZsFdm+RnN3YS+jrYx:0T+Vc1G+8OSka/Y7FBtdYS+jY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001-2015 Neuxpower Solutions Ltd
InternalName: NXPowerLite
FileVersion: 6.2.12.3
CompanyName: Neuxpower Solutions Ltd
ProductName: NXPowerLite
ProductVersion: 6.2.12.3
FileDescription: NXPowerLitexfffd - Optimizer for Microsoft Office, PDF, JPEG and ZIP files
OriginalFilename: NXPowerLite.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.FJND also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051cb431 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.12642901
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.4229
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.dcd69ae2
K7GWTrojan ( 0051cb431 )
Cybereasonmalicious.f21fa2
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FJND
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.fjgn
BitDefenderTrojan.GenericKD.12642901
NANO-AntivirusTrojan.Win32.Encoder.evqdji
MicroWorld-eScanTrojan.GenericKD.12642901
TencentWin32.Trojan.Raasc.Auto
Ad-AwareTrojan.GenericKD.12642901
SophosMal/Generic-S
ComodoMalware@#1apxpagbg1v7y
BitDefenderThetaGen:NN.ZexaF.34686.Fu1@a8ZehPji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Zerber.R002C0PKU20
McAfee-GW-EditionTrojan-FKDL!B8C3DAAF21FA
FireEyeGeneric.mg.b8c3daaf21fa2ac6
EmsisoftTrojan.GenericKD.12642901 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.hwirq
eGambitUnsafe.AI_Score_87%
MicrosoftRansom:Win32/Cerber
AegisLabTrojan.Win32.Zerber.j!c
GDataTrojan.GenericKD.12642901
Acronissuspicious
McAfeeTrojan-FKDL!B8C3DAAF21FA
MAXmalware (ai score=94)
VBA32Trojan-Ransom.Zerber
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/GdSda.A
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojanSpy.Zbot!rJCN+hQGzNE
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.FFUW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.FJND?

Win32/Kryptik.FJND removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment