Malware

About “Win32/Kryptik.FNYG” infection

Malware Removal

The Win32/Kryptik.FNYG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FNYG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

www.bing.com
www.adobe.com

How to determine Win32/Kryptik.FNYG?


File Info:

crc32: 4E4F7F7C
md5: 3c439ea574e8cd751912fba378172464
name: 3C439EA574E8CD751912FBA378172464.mlw
sha1: bd8afaa106ed5f345577f1e4f5e0cb8d20ae2911
sha256: d58bfb1a84970fd13067a9029da2fe691cf7a07b24364129fb3b06758a744dce
sha512: 2ee98d24238b11636c3bc7c10e7f1a3dc4672baac7d24829337765d36c54bd751988eeb498e84fb84b6be45c884fb6c8ebab60096a38c591ae6b77a67ba7944b
ssdeep: 3072:bhAZmvq3lD++kb6YaCU6qH3SAAWSY35u318RB4k1XTdAG:1hvqlJk2vft3ScSYg3WRDWG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2015
InternalName: Wondershare
FileVersion: 3.8.0.3
LegalTrademarks: Wondershare
ProductName: Wondershare DVD Creator Crack UZ1
ProductVersion: 3.8.0.3
FileDescription: Wondershare DVD Creator Crack UZ1
OriginalFilename: DVDCreator.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.FNYG also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.JaffCrypt.5
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1046312
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Yakes.3a368991
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.574e8c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FNYG
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.shuy
BitDefenderGen:Variant.Ransom.JaffCrypt.5
NANO-AntivirusTrojan.Win32.Yakes.elhpbo
MicroWorld-eScanGen:Variant.Ransom.JaffCrypt.5
TencentWin32.Trojan.Yakes.Lkxn
Ad-AwareGen:Variant.Ransom.JaffCrypt.5
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.nq0@aCxOO9hi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1h
McAfee-GW-EditionBehavesLike.Win32.Worm.dh
FireEyeGeneric.mg.3c439ea574e8cd75
EmsisoftGen:Variant.Ransom.JaffCrypt.5 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128643
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Yakes.sh.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Ransom.JaffCrypt.5
AhnLab-V3Trojan/Win32.Yakes.C2187508
Acronissuspicious
McAfeeArtemis!3C439EA574E8
MAXmalware (ai score=100)
VBA32Trojan.Yakes
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-1h
RisingTrojan.Generic@ML.100 (RDML:QS1ST94G2EScbO6ffZO5ew)
YandexTrojan.Yakes!vNfX6H+4Xos
IkarusTrojan-Ransom.GandCrab
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.FNYG?

Win32/Kryptik.FNYG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment