Malware

Win32/Kryptik.FXOG removal guide

Malware Removal

The Win32/Kryptik.FXOG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FXOG virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Detects the presence of Wine emulator via registry key

Related domains:

ec2-52-57-202-176.eu-central-1.compute.amazonaws.com

How to determine Win32/Kryptik.FXOG?


File Info:

crc32: 57187C4F
md5: 3141af86bdd2d9896e3be7b0efbe6b1d
name: 3141AF86BDD2D9896E3BE7B0EFBE6B1D.mlw
sha1: b6fc577e0fb973530a306206d9971c33691a83d5
sha256: 5ed4cf65b29d6a8ea31c6db5264a2098d9c19f643f361eaf2ff3cec87cbb1656
sha512: 166ea649c55e3e2d76a58840e9d7b44378bea1e3ffb3cdd8241b0229f5000af549f0b3d68f848aab1b71fbd38f8b6dcdc2c4ec8a126fa8c373569a7b48b491fb
ssdeep: 12288:0rvzdSG1Um9tuPJAb2ZeReKaPfBCThjtJ5c8YsoU1fF75yLCqYzQJo:0rBSGboJIeKh9jf5vW+li5Yzf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 16.0.26431.15
ProductName: White
FileVersion: 16.0.26431.15
CompanyName: Astra
Translation: 0x0409 0x04b0

Win32/Kryptik.FXOG also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005869ac1 )
LionicAdware.Win32.FileTour.2!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2515
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacApplication.Bundler.ICLoader.5.Gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1272656
SangforTrojan.Win32.Save.a
K7GWTrojan ( 005869ac1 )
Cybereasonmalicious.6bdd2d
CyrenW32/ICLoader.AR.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.FXOG
APEXMalicious
AvastWin32:AdwareSig [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.Bundler.ICLoader.5.Gen
NANO-AntivirusTrojan.Win32.Ekstak.etmvnd
MicroWorld-eScanApplication.Bundler.ICLoader.5.Gen
TencentMalware.Win32.Gencirc.10babd94
Ad-AwareApplication.Bundler.ICLoader.5.Gen
ComodoTrojWare.Win32.Crypt.B@7o6bny
F-SecureHeuristic.HEUR/AGEN.1110903
McAfee-GW-EditionTrojan-FOAX!3141AF86BDD2
FireEyeGeneric.mg.3141af86bdd2d989
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.enl
AviraHEUR/AGEN.1110903
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.224803D
MicrosoftSoftwareBundler:Win32/ICLoader
GDataApplication.Bundler.ICLoader.5.Gen
AhnLab-V3Malware/Win32.Generic.C2194368
Acronissuspicious
McAfeeTrojan-FOAX!3141AF86BDD2
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.ICLoader
PandaTrj/Genetic.gen
RisingSpyware.Voltar!1.AF1D (CLASSIC)
YandexTrojan.GenAsa!zCzRHUjtp8k
IkarusPUA.FileTour
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove Win32/Kryptik.FXOG?

Win32/Kryptik.FXOG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment