Malware

Win32/Kryptik.FZTC removal

Malware Removal

The Win32/Kryptik.FZTC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FZTC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Lithuanian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.FZTC?


File Info:

crc32: E507BE10
md5: 5c90f5f4028586d8a1ecfa05b23601cd
name: 5C90F5F4028586D8A1ECFA05B23601CD.mlw
sha1: 3b06edb53b42183a01491c3d29a55e8c369eb323
sha256: 05d37aa4d0f7f5580510534a42b8bca18481949f162ee407169ad487267ba637
sha512: 4aa696dc6190f379156db7ae1db7e97072b3b2f57af5b5570fd0db56715870f2db8ac986dc35b967cb4b8d38dc3bee493cb20e7bc1e71e1002882b03710be94c
ssdeep: 3072:Qj1ZDK00H4xYrme6/UOjhKDgw2CCDu2rC2t6LEC7wtx:8wihMEBwHCpCIC7wr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, dvdfvdfgfhhynty56jtmj
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
Translation: 0x0809 0x04b0

Win32/Kryptik.FZTC also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053305e1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.48131
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Titirez.ky0@GCfGHDjO
CylanceUnsafe
SangforTrojan.Win32.Kryptik.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.705d40b6
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.402858
CyrenW32/Graftor.HREO-3581
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FZTC
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Titirez.ky0@GCfGHDjO
NANO-AntivirusTrojan.Win32.Nymaim.evmhov
MicroWorld-eScanGen:Heur.Mint.Titirez.ky0@GCfGHDjO
TencentWin32.Trojan.Generic.Syrw
Ad-AwareGen:Heur.Mint.Titirez.ky0@GCfGHDjO
SophosMal/Generic-R + Troj/Wonton-ACT
ComodoTrojWare.Win32.Crypt.BC@7g1pih
BitDefenderThetaGen:NN.ZexaF.34050.ky0@aCfGHDjO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.5c90f5f4028586d8
EmsisoftGen:Heur.Mint.Titirez.ky0@GCfGHDjO (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Nymaim.dsk
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.22DB00C
MicrosoftPWS:Win32/Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Mint.Titirez.ky0@GCfGHDjO
AhnLab-V3Trojan/Win32.Matrixran.R214192
Acronissuspicious
McAfeeGenericRXDR-DR!5C90F5F40285
MAXmalware (ai score=100)
VBA32Trojan.Download
MalwarebytesGandcrab.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingTrojan.Generic@ML.100 (RDML:1bHAhlSwl25h9iRhF8nGkg)
YandexTrojan.GenAsa!yl9psL85Zwc
IkarusTrojan.Win32.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GAMX!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCEpsA

How to remove Win32/Kryptik.FZTC?

Win32/Kryptik.FZTC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment