Malware

About “Win32/Kryptik.FMZJ” infection

Malware Removal

The Win32/Kryptik.FMZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FMZJ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.FMZJ?


File Info:

crc32: 33CA281C
md5: a26adeb90f9fa8c3e482dfa70f761b81
name: A26ADEB90F9FA8C3E482DFA70F761B81.mlw
sha1: 15bb15028a3b52b66ed5e9969f1806c51635265a
sha256: 3579bb831d423f0d0e094f70ba3a7f510c387d5b2c238e57c90c9ee3f8ed83f8
sha512: 7895a50702127715f825ccf0bc07922c3d01bc48fa5c931891c02f0aaf9fd36e947b5f069b67cd262cdda74b1c0bb53887e2b2b1937544a5f8e5ef629afa142f
ssdeep: 12288:7yE7/Hc+dX63wUZnuq6sYHKmIPFZK/d4p+Fcs1n3arUnJL1mosFSAMw4Blp6E/CC:7yE7/Hc+dX63pZQ7I9ZyPP1qry33sXMZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Assembly Version: 5.1.72.934
LegalCopyright: Copyright xa9Skype Technologies S.A. 2016 All rights reserved.
InternalName: Authenticode
FileVersion: 5.1.72.934
CompanyName: Skype Technologies S.A.
FileDescription: Interventions Font Misguided Cmyk
LegalTrademarks: Copyright xa9Skype Technologies S.A. 2016 All rights reserved.
Comments: Interventions Font Misguided Cmyk
ProductName: Authenticode
Languages: English
ProductVersion: 5.1.72.934
PrivateBuild: 5.1.72.934
OriginalFilename: Authenticode
Translation: 0x0409 0x04b0

Win32/Kryptik.FMZJ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005027011 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.23235
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Shade.27
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005027011 )
Cybereasonmalicious.90f9fa
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FMZJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.uwbp
BitDefenderGen:Variant.Ransom.Shade.27
NANO-AntivirusTrojan.Win32.Yakes.evdsmh
MicroWorld-eScanGen:Variant.Ransom.Shade.27
TencentWin32.Trojan.Yakes.Lkni
Ad-AwareGen:Variant.Ransom.Shade.27
SophosMal/Generic-S
ComodoMalware@#cxodppmeu1bn
BitDefenderThetaGen:NN.ZexaF.34104.Vq0@aqmzP8oi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1c
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bc
FireEyeGeneric.mg.a26adeb90f9fa8c3
EmsisoftGen:Variant.Ransom.Shade.27 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.MalwareCrypter.uppvh
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tiggre!rfn
GDataGen:Variant.Ransom.Shade.27
AhnLab-V3Trojan/Win32.Yakes.C2366627
McAfeeArtemis!A26ADEB90F9F
MAXmalware (ai score=99)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.4258149537
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-1c
RisingTrojan.Generic@ML.100 (RDML:rLQfLB+3R3ijCA+MZc9b9g)
YandexTrojan.Yakes!AQXypH4sRco
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FQUM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.FMZJ?

Win32/Kryptik.FMZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment