Malware

What is “Win32/Kryptik.FPWL”?

Malware Removal

The Win32/Kryptik.FPWL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FPWL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Nymaim malware
  • Checks the version of Bios, possibly for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

otjdlwf.net
rrjfjiqyyqf.pw
mqwfgs.com
ykrggtnoe.com
dscalvtl.pw
iaotxsly.com
kugyzmyle.net
dbaxgmjz.in
mgeew.pw
zwmttas.pw
tbdyctcvqfwj.net
qtsql.com
adtiejqoh.net
ykjiympxtbpy.pw
bwuphwg.net

How to determine Win32/Kryptik.FPWL?


File Info:

crc32: 7AE50792
md5: b4620af00f3bbbbe307207401641a1da
name: B4620AF00F3BBBBE307207401641A1DA.mlw
sha1: 0b2223b3683ad869c3366cae1cf3d86f6564888a
sha256: d072db7ee0326fe1c7e7f7034e19d4cfdf14eed2d26c1a51a8f61acc90c7c051
sha512: 4d023254876c25bf654b924dd22888f94c74dcbf5736c58b582c88733d40637fcd032bca78475be83b3786c568dea367bad58e430934aa06b4f72c84c42130d6
ssdeep: 12288:xao63ACEZdNSwOyL/G1txko6iQE0C5PAPnyQ:sF3ALNSwOyPin0h1
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.FPWL also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Brsecmon.1
FireEyeGeneric.mg.b4620af00f3bbbbe
CAT-QuickHealTrojan.Generic
ALYacTrojan.Brsecmon.1
MalwarebytesTrojan.Nymaim
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00508fc11 )
BitDefenderTrojan.Brsecmon.1
K7GWTrojan ( 00508fc11 )
Cybereasonmalicious.00f3bb
BaiduWin32.Trojan.Kryptik.bly
SymantecPacked.Generic.546
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Kryptik.13067697
NANO-AntivirusTrojan.Win32.Nymaim.emqrbb
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Nymaim.Pefi
Ad-AwareTrojan.Brsecmon.1
ComodoMalware@#3hpx9qf6dilrk
F-SecureHeuristic.HEUR/AGEN.1117603
DrWebTrojan.Nymaim.143
ZillyaTrojan.Kryptik.Win32.1104157
TrendMicroTROJ_KRYPTIK_GC310130.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.hm
EmsisoftTrojan.Brsecmon.1 (B)
IkarusTrojan-Downloader.Win32.Nymaim
JiangminTrojan.Generic.avhma
AviraHEUR/AGEN.1117603
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Regsup
MicrosoftTrojanDownloader:Win32/Silcon!rfn
ArcabitTrojan.Brsecmon.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Brsecmon.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1875542
Acronissuspicious
McAfeeTrojan-FLPA!B4620AF00F3B
TACHYONTrojan/W32.Nymaim.593408
VBA32Trojan.Regsup
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FPWL
TrendMicro-HouseCallTROJ_KRYPTIK_GC310130.UVPM
RisingTrojan.Kryptik!1.A9B0 (CLOUD)
YandexTrojan.Regsup!4Fl8I4VCXaY
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Kryptik.FQLC!tr
BitDefenderThetaGen:NN.ZexaF.34804.KqW@a4Ywqoi
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.f4b

How to remove Win32/Kryptik.FPWL?

Win32/Kryptik.FPWL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment