Malware

Win32/Kryptik.FQQL (file analysis)

Malware Removal

The Win32/Kryptik.FQQL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FQQL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.FQQL?


File Info:

crc32: 6006648A
md5: e50c3c3d79ce53097ca33a6c0991b98a
name: E50C3C3D79CE53097CA33A6C0991B98A.mlw
sha1: 19d01216e37964e6449a254883d2553353228ce4
sha256: b78bf810907fdea89c988175bf262414d5812c6c76ce2f24e31ead2aed902eef
sha512: 59f81104d888b1363d3950647f2504a4ceac2857b9cc9f4be054053ef6246ade2f6c33988c89fbf2469d68b5901f23c3a3730bcc4f6f307bf18c68f1988012dc
ssdeep: 768:tc/3aEB83lzXj3tfY/YQAJrVN1XPhJ/dT6FHicniFLSRSWS/ZNHE/V3VY:MqEB83VXjy/YXrZ1T6MciFJxNHN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.FQQL also known as:

K7AntiVirusTrojan ( 0050d3751 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10998
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A4
CylanceUnsafe
ZillyaTrojan.Spora.Win32.573
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Spora.6761bed2
K7GWTrojan ( 0050d3751 )
Cybereasonmalicious.d79ce5
CyrenW32/Nymaim.BZ.gen!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FQQL
APEXMalicious
AvastWin32:Filecoder-AY [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Agiala.32
NANO-AntivirusTrojan.Win32.Spora.enecfc
MicroWorld-eScanGen:Variant.Agiala.32
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Agiala.32
SophosMal/Generic-R + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34628.eqW@a8OW9Afi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_SPORA.F117D5
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.e50c3c3d79ce5309
EmsisoftGen:Variant.Agiala.32 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Spora.oo
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1120891
MicrosoftRansom:Win32/Spora.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Agiala.32
AhnLab-V3Trojan/Win32.Cerber.R197896
Acronissuspicious
McAfeeRansomware-FMJ!E50C3C3D79CE
MAXmalware (ai score=83)
VBA32BScope.Trojan.Enchanim
MalwarebytesRansom.Cerber
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_SPORA.F117D5
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.GenAsa!zfJwKqc3t8w
IkarusTrojan-Ransom.Cerber
FortinetW32/GenKryptik.AFCC!tr
AVGWin32:Filecoder-AY [Trj]
Qihoo-360Win32/Ransom.Filecoder.HxQB8I0A

How to remove Win32/Kryptik.FQQL?

Win32/Kryptik.FQQL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment