Malware

Win32/Kryptik.FOQJ removal tips

Malware Removal

The Win32/Kryptik.FOQJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FOQJ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/Kryptik.FOQJ?


File Info:

crc32: 0914796D
md5: b4ad92919bbb9124ee98962595f008bf
name: B4AD92919BBB9124EE98962595F008BF.mlw
sha1: 3c0c70ba17df208a24ab815aabfb7efafdabc483
sha256: 8eabda49327cf28cd31d0f51708f21d0ac211665bfb10dad93ef182d2a818787
sha512: fbd7f08604ef9240f66917279aabaede570bc46c0a882ee0b999e2ef955f5d2cf7a43c38c4c9c233e9f61a0251d7bcfc628c8413d2a2be2626f29e218222f03b
ssdeep: 12288:5g3UtRoj3UDRWZA0dbo6TFen310u4ya6LbKwObr0WtcgyNbFXABhQ9:5lQjEDB0hAeJ56LIr0ac3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Blueberry Consultants Ltd. 2016 All rights reserved.
FileVersion: 7.4.7.72
CompanyName: Blueberry Consultants Ltd.
FileDescription: Forward Drivers Each Addressing Credentials
ProductName: HevcBlowing
ProductVersion: 7.4.7.72
PrivateBuild: 7.4.7.72
Translation: 0x0409 0x04b0

Win32/Kryptik.FOQJ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.23235
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Crysis.10
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Yakes.55ba5071
Cybereasonmalicious.19bbb9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FOQJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.uzrz
BitDefenderGen:Variant.Ransom.Crysis.10
NANO-AntivirusTrojan.Win32.Yakes.evjmmd
MicroWorld-eScanGen:Variant.Ransom.Crysis.10
TencentWin32.Trojan.Yakes.Pftd
Ad-AwareGen:Variant.Ransom.Crysis.10
SophosMal/Generic-S
ComodoMalware@#2myys8i3viqvr
F-SecureHeuristic.HEUR/AGEN.1101366
BitDefenderThetaGen:NN.ZexaF.34678.Ru0@amV1Vqji
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.b4ad92919bbb9124
EmsisoftGen:Variant.Ransom.Crysis.10 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1101366
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmTrojan.Win32.Yakes.uzrz
GDataGen:Variant.Ransom.Crysis.10
AhnLab-V3Trojan/Win32.Yakes.C2373751
Acronissuspicious
McAfeeArtemis!B4AD92919BBB
MAXmalware (ai score=99)
VBA32BScope.Trojan.Wacatac
PandaTrj/CI.A
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.Crypt
FortinetW32/Generic.FOQJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Botnet.Yakes.HwoCEpsA

How to remove Win32/Kryptik.FOQJ?

Win32/Kryptik.FOQJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment