Malware

Win32/Kryptik.FZOQ information

Malware Removal

The Win32/Kryptik.FZOQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FZOQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Hebrew
  • Network activity detected but not expressed in API logs

Related domains:

edgedl.gvt1.com
update.googleapis.com

How to determine Win32/Kryptik.FZOQ?


File Info:

crc32: 90251E0F
md5: 93681835bb54167d0e71be83637d4f2a
name: 93681835BB54167D0E71BE83637D4F2A.mlw
sha1: 95a7317ffc9b53be3896ed2cfdd996ca2e573dc6
sha256: f1bd2ce3e16bcfe3dbaee2043f1705196d8becf80be213e453de9185e32ffe0d
sha512: ec2af947d3502ade75570860cfa5af178c4a04875ebefbe1e8be27a7f40039035f8a71c806eff2a95f059ed4a207d2fffb0b19f92e6d106705c6e539ce760b4c
ssdeep: 3072:lYogiwLMiExMIm3YdSaYJO5Ml+phSmYPbsPdyHU6tCfwcym2rOcpg5+7vIh+MLG4:ldgEedAS/O5pxYPbsz1wp5pP7vI40F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

XXXXXXXXXXXXXXXXXX: ileDescription
CompanyName: TEchSmith Corporation
Translation: 0x0409 0x04e4

Win32/Kryptik.FZOQ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Cerber.495
FireEyeGeneric.mg.93681835bb54167d
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Ransom.Cerber.495
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderGen:Variant.Ransom.Cerber.495
K7GWTrojan ( 005081281 )
Cybereasonmalicious.5bb541
CyrenW32/S-3e1d46f2!Eldorado
SymantecPacked.Generic.459
BaiduWin32.Trojan.Kryptik.ayf
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Cerber-9779681-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.emkmvz
TencentMalware.Win32.Gencirc.10b1b6d8
Ad-AwareGen:Variant.Ransom.Cerber.495
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Ransom.Cerber.BF@6tebck
F-SecureHeuristic.HEUR/AGEN.1124977
DrWebTrojan.Encoder.4691
ZillyaTrojan.Kryptik.Win32.1089302
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Dropper.hm
EmsisoftGen:Variant.Ransom.Cerber.495 (B)
GDataGen:Variant.Ransom.Cerber.495
JiangminTrojan.Zerber.bjq
AviraHEUR/AGEN.1124977
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Ransom.Cerber.495
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/Cerber
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-CBER!93681835BB54
MAXmalware (ai score=89)
VBA32BScope.Trojan.Jorik
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FZOQ
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingTrojan.Kryptik!1.A877 (CLOUD)
YandexTrojan.GenAsa!V3V5gUBXs/Q
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Zamg.O!tr
AVGWin32:Filecoder-BG [Trj]
AvastWin32:Filecoder-BG [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Filecoder.HxQBuIEA

How to remove Win32/Kryptik.FZOQ?

Win32/Kryptik.FZOQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment