Malware

What is “Win32/Kryptik.FUNJ”?

Malware Removal

The Win32/Kryptik.FUNJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FUNJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.FUNJ?


File Info:

name: C6DE43720423BE5C63E4.mlw
path: /opt/CAPEv2/storage/binaries/a31d0f88afa73194ebddf9fdd6739a0eacbf60a47a2d1b555eec65aa9f9a8161
crc32: 2FC5ED2B
md5: c6de43720423be5c63e4bec4c0cafdd9
sha1: 350073d53e512dfacbd805af2150496e06573901
sha256: a31d0f88afa73194ebddf9fdd6739a0eacbf60a47a2d1b555eec65aa9f9a8161
sha512: aa2fcea041ff46d1de58270173e035415e641c3af2d7888ccad4486942e57088a4a69c51c8ee0ab940b36b9064ab7a825086454919579c4b3765f80a73a46660
ssdeep: 12288:i7777XaQoe2O/gvWMzSkQaCfRb4+PkTvMDfjVV:i7777XVoe/YOwfQdfxpkTUlV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FC4E0269CE380F3F5849534D735C576EEAEE4F0030693BB574C92ABC725381B4DA62A
sha3_384: 04fb12be915a6009412e8524606ff7a1e84988c0f29220b591b767428be7d6ebc73e9058c4d9f05523f5f7b5c55030f5
ep_bytes: e88f3b0000e91efeffffb8102a4000c3
timestamp: 2014-04-08 23:26:39

Version Info:

0: [No Data]

Win32/Kryptik.FUNJ also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mikey.116291
FireEyeGeneric.mg.c6de43720423be5c
McAfeeTrojan-FEBH!C6DE43720423
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056f46b1 )
K7GWTrojan ( 0056f46b1 )
Cybereasonmalicious.20423b
BitDefenderThetaGen:NN.ZexaF.36318.JmW@aGG0tcu
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.FUNJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.116291
NANO-AntivirusTrojan.Win32.Yakes.cytpcl
AvastWin32:Crypt-RGM [Trj]
TencentWin32.Trojan.Generic.Fflw
EmsisoftGen:Variant.Mikey.116291 (B)
F-SecureHeuristic.HEUR/AGEN.1318602
VIPREGen:Variant.Mikey.116291
TrendMicroMal_Gatak
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
Trapminemalicious.moderate.ml.score
SophosMal/Gatak-D
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Mikey.116291
AviraHEUR/AGEN.1318602
Antiy-AVLTrojan/Win32.Yakes
XcitiumTrojWare.Win32.Injector.BABP@59nxt6
ArcabitTrojan.Mikey.D1C643
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C369027
VBA32BScope.Trojan.Gatak
ALYacGen:Variant.Mikey.116291
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3208578877
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Gatak
IkarusTrojan.Crypt.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.BAPB!tr
AVGWin32:Crypt-RGM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Kryptik.FUNJ?

Win32/Kryptik.FUNJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment