Malware

About “Win32/Kryptik.FVYF” infection

Malware Removal

The Win32/Kryptik.FVYF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FVYF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • EternalBlue behavior
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.FVYF?


File Info:

crc32: ECE4D774
md5: e4505cc71ca3d709c51be956fe460f63
name: E4505CC71CA3D709C51BE956FE460F63.mlw
sha1: 8a668cb413310a6515e0b5a3e6bbae7df10c7112
sha256: f0d7d9215459b9b2a3c12e857b0eb6896e9ba206692bfcee751470d46d257d5e
sha512: 851ec798a3b85c513b20eb65fa961f33d8291946ee5266c3db966295d96547bfeea07c31573790be981fb7af220bd05cbfd2d73bbef8fe1cd69bc8274560a0fd
ssdeep: 6144:xPSWCfUxuNuUelUa4Z/uIjhXOmqGWQnLOpv295mPRNLIaj8X:xKWCNbn/dZ89Ma+aIaIX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2015
InternalName: SmartRAM
FileVersion: 9.0.0.22
CompanyName: IObit
LegalTrademarks: IObit
Comments: Smart RAM
ProductName: Smart RAM
ProductVersion: 9.0.0.0
FileDescription: Monitors and Optimizes memory usage to increase available physical memory.
OriginalFilename: SmartRAM.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.FVYF also known as:

BkavW32.AIDetectGBM.malware.02
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
MicroWorld-eScanTrojan.GenericKDZ.70920
CAT-QuickHealRansom.Cerber.A4
Qihoo-360Win32/Trojan.Ransom.c1a
McAfeeRansomware-GCQ!E4505CC71CA3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zerber.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054f2ec1 )
BitDefenderTrojan.GenericKDZ.70920
K7GWTrojan ( 0054f2ec1 )
Cybereasonmalicious.71ca3d
BitDefenderThetaGen:NN.ZexaF.34590.Cq0@auxRa@kj
CyrenW32/Ransom.GX.gen!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.d27aabc2
NANO-AntivirusTrojan.Win32.Zerber.esdstb
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKDZ.70920
EmsisoftTrojan.GenericKDZ.70920 (B)
ComodoTrojWare.Win32.Zonidel.AY@7kn16e
F-SecureHeuristic.HEUR/AGEN.1112219
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionRansomware-GCQ!E4505CC71CA3
FireEyeGeneric.mg.e4505cc71ca3d709
SophosML/PE-A + Mal/Cerber-AL
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Generic.ftxfh
AviraHEUR/AGEN.1112219
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Generic.D11508
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Cerber.AL
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
VBA32BScope.Trojan.Encoder
ALYacTrojan.GenericKDZ.70920
MAXmalware (ai score=100)
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FVYF
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
RisingTrojan.Kryptik!1.AD41 (CLASSIC)
YandexTrojan.GenAsa!Lih+aInBhxg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Zamg.O!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.FVYF?

Win32/Kryptik.FVYF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment