Malware

Win32/Kryptik.FOQY malicious file

Malware Removal

The Win32/Kryptik.FOQY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FOQY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Win32/Kryptik.FOQY?


File Info:

crc32: C0EC3B5C
md5: a8d1b5af1c8f67772d6e2f3b6abb21ed
name: A8D1B5AF1C8F67772D6E2F3B6ABB21ED.mlw
sha1: 00353bc41f50f1864810e0d3075a6c2e2582f14b
sha256: 07cdcd870c8311e52cabc6b27225b720e48833bdc9146051c8594bd32f136a31
sha512: 2a068492cf13d4b242af11a9cd5df35d2d8995ce0421f8eaa1c354875a5e15d258df8a8aabc75d89b6934be9a91646af4b660b02b81ed63f452b9ac6da5f5af1
ssdeep: 768:MKEUvcMdNrpfxUZ9eoRGQ8x3ahG2oeZfwI2plWVI84VRFzJD5dNrp8dNrp:MpUvTkGPQ8VetdZfwIwWSlvO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.FOQY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005073351 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10103
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A4
ALYacGen:Variant.Crypt.38
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Spora.00702da6
K7GWTrojan ( 005054af1 )
Cybereasonmalicious.f1c8f6
BaiduWin32.Trojan.Kryptik.bka
CyrenW32/Spora.C.gen!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FOQY
APEXMalicious
AvastWin32:Filecoder-BD [Trj]
ClamAVWin.Ransomware.Spora-7086056-0
KasperskyHEUR:Trojan-Ransom.Win32.Spora.pef
BitDefenderGen:Variant.Crypt.38
NANO-AntivirusTrojan.Win32.Encoder.evdwrc
MicroWorld-eScanGen:Variant.Crypt.38
TencentWin32.Trojan.Sporalocker.Lpkz
Ad-AwareGen:Variant.Crypt.38
SophosMal/Generic-R + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34608.eqW@a0Ur@rgc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM3B
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.a8d1b5af1c8f6777
EmsisoftTrojan-Ransom.Spora (A)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1105007
eGambitUnsafe.AI_Score_97%
MicrosoftRansom:Win32/Spora
ArcabitTrojan.Crypt.38
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Crypt.38
AhnLab-V3Trojan/Win32.Spora.C1801377
Acronissuspicious
McAfeeRansom-Spora!A8D1B5AF1C8F
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Spora
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.SM3B
RisingRansom.Spora!8.E3EE (CLOUD)
IkarusTrojan-Ransom.Spora
FortinetW32/Kryptik.GKVH!tr
AVGWin32:Filecoder-BD [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Filecoder.HxQBgVAA

How to remove Win32/Kryptik.FOQY?

Win32/Kryptik.FOQY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment