Malware

About “Win32/Kryptik.FXWP” infection

Malware Removal

The Win32/Kryptik.FXWP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FXWP virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key

Related domains:

ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Win32/Kryptik.FXWP?


File Info:

crc32: A29C79FA
md5: 1c1ba96772996439368fba65e152ff82
name: 1C1BA96772996439368FBA65E152FF82.mlw
sha1: f2c157dafe42d04d92416ed3634940561000229e
sha256: 1a43932533442d33c0b6e93fa03376846a02531e64d52dde6a31b1c168a8c1ca
sha512: ff4cc961fa10efeb32a972fe2e4f873af4fe6d3e1daf8332fbb7f721e5486dbc6370615446bd0f28cf96936a0f59fb14015ee2ec40969d155e71664a1e755600
ssdeep: 12288:CE6kvRGx1RlOgwojHjyBuMJZyU7xtyDoa8+T9HHHkH9tuzblL1GzHGYKR+kP:56ERc1LTwoSuMJZxfsDxHHHvNLw7GYI9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 17.1.26432.16
ProductName: White
FileVersion: 17.1.26432.16
CompanyName: Astra
Translation: 0x0409 0x04b0

Win32/Kryptik.FXWP also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005869f11 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2507
CynetMalicious (score: 100)
ALYacApplication.Bundler.ICLoader.5.Gen
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaAdWare:Win32/Katusha.b5d5ddcf
K7GWTrojan ( 005869f11 )
Cybereasonmalicious.772996
CyrenW32/ICLoader.AR.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.FXWP
APEXMalicious
AvastWin32:AdwareSig [Adw]
ClamAVWin.Malware.Zusy-9804702-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.Bundler.ICLoader.5.Gen
NANO-AntivirusTrojan.Win32.Ekstak.etwleh
MicroWorld-eScanApplication.Bundler.ICLoader.5.Gen
TencentMalware.Win32.Gencirc.10bac063
Ad-AwareApplication.Bundler.ICLoader.5.Gen
SophosMal/Generic-S
ComodoTrojWare.Win32.Crypt.B@7o6bny
F-SecureTrojan.TR/ICLoader.Gen8
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FNZS!1C1BA9677299
FireEyeGeneric.mg.1c1ba96772996439
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.eoz
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2259513
MicrosoftPUADlManager:Win32/InstallCube
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataApplication.Bundler.ICLoader.5.Gen
AhnLab-V3Trojan/Win32.Agent.R210601
Acronissuspicious
McAfeeTrojan-FNZS!1C1BA9677299
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.ICLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!VdzuVNT20Ag
IkarusPUA.FileTour
MaxSecureTrojan.Packed.WIN32.Katusha.gen_216060
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.FXWP?

Win32/Kryptik.FXWP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment