Malware

Win32/Kryptik.FLDX removal tips

Malware Removal

The Win32/Kryptik.FLDX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FLDX virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of Cerber ransomware
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to access Bitcoin/ALTCoin wallets
  • Creates a known Cerber ransomware decryption instruction / key file.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.FLDX?


File Info:

crc32: 0B08920D
md5: baaf59917644780610a7f5f950ec915f
name: BAAF59917644780610A7F5F950EC915F.mlw
sha1: c0edc6aa42727f9903bf790e07a64c3657623ea0
sha256: 8182cf79396339fde2abf3e93345c89f266012db2a978019d41745d79d0b943d
sha512: bdbbab518b40c2a2f28e5d64b5e02a5d9283fa484f38420e33d1df4f1d4bb2449350c1b899c22617cb40e9fafb174cbee0f1e83d1ffb5d27708ed3158f6460ec
ssdeep: 6144:+IU/RKs7QHNYmgnNbsYzze0/cOWeD2UIXuhB7ItlQ2:+/Is7QHNYmQ80/TWetIezItlQ2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompanyName: A shampoo
Translation: 0x0409 0x04b0

Win32/Kryptik.FLDX also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.770897
FireEyeGeneric.mg.baaf599176447806
CAT-QuickHealRansom.Cerber.A4
McAfeeRansomware-GCQ!BAAF59917644
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderGen:Variant.Razy.770897
K7GWTrojan ( 005224381 )
Cybereasonmalicious.176447
BaiduWin32.Trojan.Kryptik.bin
CyrenW32/S-3e1d46f2!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Ransomware.Cerber-5970076-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.e50a54f2
NANO-AntivirusTrojan.Win32.Menti.eumhsm
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Variant.Razy.770897
EmsisoftGen:Variant.Razy.770897 (B)
ComodoTrojWare.Win32.Filecoder.BD@6qki3k
F-SecureHeuristic.HEUR/AGEN.1121403
DrWebTrojan.MulDrop7.8883
ZillyaTrojan.Kryptik.Win32.995186
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosML/PE-A + Mal/Cerber-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.apkgp
MaxSecureTrojan.Malware.7164915.susgen
AviraHEUR/AGEN.1121403
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber.H
ArcabitTrojan.Razy.DBC351
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.770897
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.Jq1@auWLQfni
ALYacGen:Variant.Razy.770897
MAXmalware (ai score=100)
VBA32BScope.Trojan.Menti
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FLDX
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingTrojan.Kryptik!1.AE9C (CLOUD)
YandexTrojan.GenAsa!QYiBnDemiX8
IkarusTrojan-Ransom.Cerber
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Cerber.HgIASOYA

How to remove Win32/Kryptik.FLDX?

Win32/Kryptik.FLDX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment