Malware

Win32/Kryptik.FWLM (file analysis)

Malware Removal

The Win32/Kryptik.FWLM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FWLM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • EternalBlue behavior
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.FWLM?


File Info:

crc32: 842FA1DC
md5: 818d11aab773ba094119be32e2a26893
name: 818D11AAB773BA094119BE32E2A26893.mlw
sha1: 25a95da23099d02e2318ae345de147ffbbf77632
sha256: f17649565e73e4761df7a46bf69e8c1fda8402d55e529bccf364687547f41625
sha512: b26c8912727ae5e5896c9c4e7c60fa1b36cb4dad807ee92825406215d50b77486b5fae7d789c0ae80a978329aef9e72fb7a1963ef8b5a8b356c6da4fc4658787
ssdeep: 12288:ZRCvq903BEgk/0NFhlIWQqz/1mRvODPyX:rCy90Gz/kF3VQqL1mRvODKX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Tonec Inc., Copyright xa9 1999 - 2015
InternalName: IDMGrHlp
FileVersion: 6, 22, 1, 1
CompanyName: Tonec Inc.
LegalTrademarks: Internet Download Manager
Comments: Auxiliary program for Internet Download Manager
ProductName: Internet Download Manager
ProductVersion: 6, 22, 1, 1
FileDescription: Internet Download Manager module
OriginalFilename: IDMGrHlp.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.FWLM also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.40326
FireEyeGeneric.mg.818d11aab773ba09
CAT-QuickHealRansom.Cerber.A4
McAfeeRansomware-GCQ!818D11AAB773
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005188bf1 )
BitDefenderTrojan.GenericKDZ.40326
K7GWTrojan ( 0039f5721 )
Cybereasonmalicious.ab773b
BitDefenderThetaGen:NN.ZexaF.34590.fr3@aq3KFhji
SymantecPacked.Generic.459
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Cerber-9779368-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.eskwtg
RisingTrojan.Kryptik!1.AD41 (CLOUD)
Ad-AwareTrojan.GenericKDZ.40326
SophosML/PE-A + Mal/Cerber-AL
ComodoTrojWare.Win32.Bulta.GR@7k46qi
F-SecureHeuristic.HEUR/AGEN.1117922
DrWebTrojan.Encoder.4691
ZillyaTrojan.Kryptik.Win32.1268650
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionBehavesLike.Win32.Ransomware.th
EmsisoftTrojan.GenericKDZ.40326 (B)
JiangminTrojan.Zerber.dba
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1117922
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Cerber.L!bit
ArcabitTrojan.Generic.D9D86
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Cerber.AL
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
VBA32Trojan-Ransom.Zerber
MAXmalware (ai score=100)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FWLM
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
TencentMalware.Win32.Gencirc.10b3f2be
SentinelOneStatic AI – Malicious PE
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Zamg.O!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM20.1.B857.Malware.Gen

How to remove Win32/Kryptik.FWLM?

Win32/Kryptik.FWLM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment