Malware

Win32/Kryptik.FTPN removal

Malware Removal

The Win32/Kryptik.FTPN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FTPN virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (24 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.crcsi.org
www.udesign.biz
www.spanesi.com
www.vitaindu.com
www.rs-ag.com
www.pr-park.com
www.2print.com
www.c9dd.com
www.item-pr.com
www.owsports.ca
www.abdg.com
www.vazir.se
www.cel-cpa.com
www.reglera.com
www.netcr.com
www.valdal.com
www.transsib.com
www.tyrns.com
www.t-tre.com
www.ftchat.com
www.speelhal.net
www.abart.pl
www.photo4b.com
www.ottospm.com
www.pohlfood.com
www.medisa.info
www.ora-ito.com
www.ka-mo-me.com
www.mobilnic.net
www.depalo.com
www.wifi4all.nl
www.com-sit.com
www.alteor.cl
www.jroy.net
www.ora.ecnet.jp
www.pwd.org
www.iamdirt.com
www.yumgiskor.kz
www.gpthink.com
www.nelipak.nl
www.jacomfg.com
www.elpro.si
www.aevga.com
www.koz1.net
www.fink.com
www.usadig.com
www.nqks.com
www.credo.edu.pl
www.yoruksut.com
www.medius.si
www.stnic.co.uk
www.edimart.hu
www.tc17.com
www.h-f.net
www.tvtools.fi
www.stajum.com
www.waldi.pl
www.myropcb.com
www.cokocoko.com
yoruksut.com
oozkranj.com
xinhui.net
shenhgts.net
any-s.net
piacton.com
cpwpb.com
mxs.mail.ru
icd-host.com
uster.com
dspears.com
simetar.com
aluminox.es
samtv.ro
cubodown.com
bidroll.com
in1.smtp.messagingengine.com
mail7.digitalwaves.co.nz
fifa-ews.com
paraski.org
akdeniz.nl
gydrozo.ru
avse.hu
sgk.home.pl
bigzz.by
web-york.com
wolffkran.de
kevyt.net
at-shun.com
amba-tc.si
vfcindia.com
geecl.com
aba.org.eg
calvinly.com
komie.com
clysma.com
likangds.com
riwn.org
sanfotek.net
karmy.com.pl
nolaoig.org
zemarmot.net
envogen.com
ultibax.org
mcseurope.nl
mikihan.com
keio-web.com
cqdgroup.com
cjcagent.com
shittas.com
willsub.com
cjborden.com
shiner.com
reproar.com
doggybag.org
esmoke.net
workplus.hu
popbook.com
skypearl.com
avc.com.sa
duiops.net
www.jenco.co.uk
www.quadlock.com
www.kernsafe.com
www.valselit.com
www.fcwcvt.org
rappich.de
amele.com
skgm.ru
bosado.com
snf.it
michiana.org
amic.at
notis.ru
www.wnsavoy.com
orbitgas.com
shesfit.com
78san.com
www.holleman.us
www.mqs.com.br
amerifor.com
adventist.ro
agulatex.com
www.railbook.net
nme.co.jp
mondopp.net
kairel.com
www.fnw.us
www.domon.com
jnf.at
midap.com
gcss.com
umcor.am
pers.com
fundeo.com
wvs-net.de
lyto.net
yasuma.com
tbvlugus.nl
isom.org
www.hummer.hu
hubbikes.com
www.xaicom.es
atb-lit.com
ciicsc.com
www.pb-games.com
kamptal.at
cpmteam.com
koz1.net
polprime.com
www.lrsuk.com
ccrsi.org
rtcasey.com
invictus.pl
johnlyon.org
www.fe-bauer.de
roewer.de
portoccd.org
msl-lock.com
awal.ws
acraloc.com
www.nunomira.com
juso-gr.ch
semuk.com
webways.com
eos-i.com
www.snugpak.com
biurohera.pl
ludomemo.com
rkengg.com
slower.it
ktenergo.ru
com-edit.fr
atis-sk.ca
from30ty.com
aoinko.net
beafin.com
univi.it
ascc.org.au
someikan.com
tozzhin.com
plaske.ua
multip.hu
pro-fa.com
ncn.de
ccssinc.com
c-drop.net
mkm-gr.com
fdlymca.org
lpver.com
linac.co.uk
uhsa.edu.ag
fogra.com.pl
gbp-jp.com
scip.org.uk
ftmobile.com
araax.com
sokuwan.net
valselit.com
zugseil.com
nlcv.bas.bg
ntc.edu.au
bggs.com
actmin.com
forbin.net
cbras.com
redgiga.com
89gospel.com
burstner.ru
ftchat.com
shztm.ru
btsi.com.ph
toundo.net
adeesa.net
webband.com
nekono.net
sledsport.ru
assideum.com
akr.co.id
anduran.com
gbmfg.com
deckoviny.cz
wanoa.com
stopllc.com
ossir.org
chzko.ru
leapc.com
host.do
revoldia.net
www.naoi-a.com
kavram.com
e-asset.net
www.dayvo.com
www.vexcom.com
unicus.jp
websy.com
nels.co.uk
kallman.net
canmore.com
www.x0c.com
top1oil.com
www.fnsds.org
www.pupi.cz
nettle.pl
gphpedit.org
holp-ai.com
wnit.org
absblast.com
infotech.pl
www.wkhk.net
htsmx.net
www.pdqhomes.com
averwin.com
missnue.com
bible.org
smtp.sbcglobal.yahoo.com
www.pcgrate.com
yhsll.com
angework.com
okashimo.com
www.findbc.com
ludea.cz
haigh-me.com
www.otena.com
n23china.com
ie-roi.com
www.sclover3.com
dog-jog.net
madjek.com
vonparis.com
hamaker.net
arowines.com
smitko.net
kursavto.ru
mjrcpas.com
zupraha.cz
pertex.com
hazmatt.com
ymlp15.net
106west.com
e-kami.net
iranytu.net
themark.org
gujarat.com
karila.fr
tcpoa.com
jsaps.com
ruzee.com
sidepath.com
ssm.ch
cnti.krsn.ru
fortknox.bm
kumaden.com
shteeble.com
apcotex.com
hbfuels.com
h-et-l.com
cvswl.org
webavant.com
ifesnet.com
pcoyuncu.com
cbaben.com
siongann.com
usadig.com
listel.co.jp
dayvo.com
nettlinx.org
t-trust.jp
nt-hat.com
sjbmw.com
peminet.net
canasil.com
www.evcpa.com
www.jchysk.com
mijash3.com

How to determine Win32/Kryptik.FTPN?


File Info:

crc32: EB3B9253
md5: f04bb83de06f653f438efd8062a0e007
name: nnstp.exe
sha1: 8e215b3189891a0e57b9cfd913b95adb1517b9b1
sha256: 288c5039d51fd1fe34cf26190fe2aeb0bafbbf8e60af7044e96ad10537a8d7d9
sha512: 625b7edbd45835763240837b8f1c43353ef00375de2d2358e55598136099214fdc8406508e4d5559b3075f0fb45d8bbed2032400de1bdd107428d188ac2383cd
ssdeep: 3072:FcK7QSowMO79hzXAeBtQ7sQL/lL6tBNkGz/5K+irLCsd2Ih5jmv9FJ3MYYOYYYY5:rMm9FXAeBNQDFKKGJ2LD2Ibe37
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: CassepTools Inc Copyright xc2xa9 2000 - 2014 KG and its Licensors
InternalName: Nticed
FileVersion: 2.8.8.4
CompanyName: CassepTools Inc
PrivateBuild: 2.8.8.4
LegalTrademarks: CassepTools Inc Copyright xc2xa9 2000 - 2014 KG and its Licensors
Comments: Contents Prepares Conversations Datacontext
ProductName: Nticed
ProductVersion: 2.8.8.4
FileDescription: Contents Prepares Conversations Datacontext
OriginalFilename: Nticed.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.FTPN also known as:

MicroWorld-eScanTrojan.GenericKD.6329546
FireEyeGeneric.mg.f04bb83de06f653f
CAT-QuickHealTrojan.Cutwail
McAfeeRDN/Generic.cui
VIPRETrojan.Win32.Cutwail
AegisLabTrojan.Win32.Cutwail.tpdv
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.6329546
K7GWTrojan ( 00521ad71 )
K7AntiVirusTrojan ( 00521ad71 )
TrendMicroTROJ_CUTWAIL.USVZ
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6409643-0
GDataTrojan.GenericKD.6329546
KasperskyTrojan.Win32.Cutwail.wxi
AlibabaTrojan:Win32/Cutwail.1deb64d4
NANO-AntivirusTrojan.Win32.Cutwail.ewmcnr
RisingTrojan.Generic@ML.99 (RDMK:tL0FQXCLlWAMtY8kFAsVKw)
Ad-AwareTrojan.GenericKD.6329546
SophosMal/Generic-S
ComodoMalware@#l2dvfgq2o70d
F-SecureHeuristic.HEUR/AGEN.1037230
DrWebTrojan.DownLoad.64914
ZillyaTrojan.Cutwail.Win32.1398
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.cui
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.6329546 (B)
IkarusTrojan.Win32.Krypt
JiangminTrojan.Cutwail.fe
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1037230
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Cutwail
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D6094CA
ZoneAlarmTrojan.Win32.Cutwail.wxi
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Trojan/Win32.Cutwail.C2322828
Acronissuspicious
ALYacTrojan.GenericKD.6329546
VBA32Trojan.Cutwail
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FTPN
TrendMicro-HouseCallTROJ_CUTWAIL.USVZ
YandexTrojan.Cutwail!6taE9AbBKko
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GKUA!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.de06f6
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.69e

How to remove Win32/Kryptik.FTPN?

Win32/Kryptik.FTPN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment