Malware

Win32/Kryptik.FRVT (file analysis)

Malware Removal

The Win32/Kryptik.FRVT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FRVT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.FRVT?


File Info:

crc32: A80B6B20
md5: 200b1f4bda67669323193bd80449d6d3
name: 200B1F4BDA67669323193BD80449D6D3.mlw
sha1: 0149af470e97ac8c389417646b0e43abbcc5af21
sha256: 4d7fc8347c65da921439433a419d78e5abbd72e7ff6da93b84377ec83c03a75e
sha512: 74fa3278da9d1b7fe32f92eb1d1eed43cfd92723716ca6f7f9841d5ecdb3a3e91ab38cf698a69154a521a89147126b0da4ee7612e37ca70da5698266ff8e092e
ssdeep: 6144:eR4GbVOUtKXVgcNX3RVR+64R8cog9kqn2KRmgWDVb/ii4mnj0DD0z:8pVuSG9+VRTYgAx/Ji0z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999 - 2011 SpeedBit Ltd.
FileVersion: 1, 0, 0, 3
CompanyName: Speedbit Ltd.
PrivateBuild: 2599
Comments: 2599
ProductName: DAP Error Report
ProductVersion: 1, 0, 0, 3
FileDescription: DAP Error Report
OriginalFilename: dapxrpt.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.FRVT also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.837267
FireEyeGeneric.mg.200b1f4bda676693
CAT-QuickHealRansom.Cerber.A4
McAfeeRansomware-FXM!200B1F4BDA67
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderGen:Variant.Razy.837267
K7GWTrojan ( 005224381 )
Cybereasonmalicious.bda676
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/S-502d1467!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-6308667-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.24d09f96
NANO-AntivirusTrojan.Win32.Zerber.eogilk
ViRobotTrojan.Win32.Cerber.456704.C
RisingTrojan.Kryptik!1.AACA (CLOUD)
Ad-AwareGen:Variant.Razy.837267
TACHYONRansom/W32.Cerber.456704.G
EmsisoftGen:Variant.Razy.837267 (B)
ComodoTrojWare.Win32.Ransom.Cerber.EW@73u1y1
F-SecureHeuristic.HEUR/AGEN.1129194
DrWebTrojan.Encoder.11198
ZillyaTrojan.Zerber.Win32.2613
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
SophosML/PE-A + Mal/Cerber-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.buv
WebrootW32.Ransom.Gen
AviraHEUR/AGEN.1129194
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber.K
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.837267
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
VBA32BScope.Trojan.Encoder
ALYacGen:Variant.Razy.837267
MAXmalware (ai score=86)
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FRVT
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
TencentMalware.Win32.Gencirc.10b58aaf
YandexTrojan.GenAsa!qQ6NIot1edw
IkarusTrojan-Ransom.Cerber
FortinetW32/Kryptik.HGZD!tr
BitDefenderThetaGen:NN.ZexaF.34590.Bq0@a4xYehni
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Generic.HxQB42AA

How to remove Win32/Kryptik.FRVT?

Win32/Kryptik.FRVT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment