Malware

Win32/Kryptik.FXCT removal guide

Malware Removal

The Win32/Kryptik.FXCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FXCT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to identify installed analysis tools by a known file location
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects Sandboxie using a known mutex
  • Attempts to modify proxy settings
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.FXCT?


File Info:

crc32: EB826B73
md5: ed83c1b427720dcbf26843cb5794d624
name: ED83C1B427720DCBF26843CB5794D624.mlw
sha1: 9f99fb01a0fd008242ab7f577254b0e2dc817fec
sha256: b5c925a68f1359d9792bc6abb7b99856ab15ae5d847391cc2210404f0c22c481
sha512: 3d1421966e8041f62c002f40274019bc438847bbc30fc2e3d69426479dc225b0e8fb68c8f8d1511d1331fc396218731ec409336abd3415cc51d22499132e8a0b
ssdeep: 3072:+LRmF7W8ojW0lJkAl2KX2MfzqPNzSrre61T6HIG2utR6eO:ZxoS0rlRuzWeGT6HIG6F
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.FXCT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051918c1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.11620
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.ZZ6
ALYacTrojan.GenericKDZ.40604
CylanceUnsafe
ZillyaTrojan.GenericKDZ.Win32.9406
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Zuepan.e6046ff0
K7GWTrojan ( 0051918c1 )
Cybereasonmalicious.427720
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FXCT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Locky-7082144-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.40604
NANO-AntivirusTrojan.Win32.Encoder.etafjp
ViRobotTrojan.Win32.Locky.604672.D
MicroWorld-eScanTrojan.GenericKDZ.40604
TencentMalware.Win32.Gencirc.10ba0f90
Ad-AwareTrojan.GenericKDZ.40604
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Dynamer.FXCT@7akob8
BitDefenderThetaGen:NN.ZexaF.34628.lqW@a08hGoh
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Ransomware.cc
FireEyeGeneric.mg.ed83c1b427720dcb
EmsisoftTrojan-Ransom.Locky (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.dmm
AviraHEUR/AGEN.1120889
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Zuepan.A
ArcabitTrojan.Generic.D9E9C
GDataTrojan.GenericKDZ.40604
AhnLab-V3Win-Trojan/RansomCrypt.Exp
Acronissuspicious
McAfeeRansom-Locky!ED83C1B42772
MAXmalware (ai score=100)
VBA32Trojan.FakeAV.01657
MalwarebytesRansom.Locky
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SMALY0
RisingTrojan.Kryptik!1.AE8C (CLASSIC)
YandexTrojan.GenAsa!8z0Ak9UjeVE
IkarusTrojan-Ransom.Locky
FortinetW32/Kryptik.GKNL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBuCMA

How to remove Win32/Kryptik.FXCT?

Win32/Kryptik.FXCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment