Malware

Win32/Kryptik.FZVO removal tips

Malware Removal

The Win32/Kryptik.FZVO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.FZVO virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.FZVO?


File Info:

crc32: 7D1205FE
md5: a65e878343847902737d9679d05bc317
name: A65E878343847902737D9679D05BC317.mlw
sha1: f07a8a8e4d3b398f57c3a6bfabd36a0afc3290e0
sha256: 92dd9d88f0f10891d28b3b1a31bf0c85101b454af746890070d9100b808149ae
sha512: 3c2c1cfb973ef0ec93c4ddd03175592ad2770715e1f36a9135017aa9b9add75f5efbfe44a620ed4259b44caa90d0c3a1b184b8020d218b3fb7286d6c935ed076
ssdeep: 24576:eejaAn6KtkoGfywGFn1/HWCCqNePk3KN:nlrqlar1fWDMqk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Mozilla Corporation
FileVersion: 38.2.0
CompanyName: Mozilla Corporation
LegalTrademarks: Thunderbird is a Trademark of The Mozilla Foundation.
ProductName: Thunderbird
ProductVersion: 38.2.0
FileDescription: Mozilla Maintenance Service Installer
OriginalFilename: maintenanceservice_installer.exe
Translation: 0x0000 0x04b0

Win32/Kryptik.FZVO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Hottrend.based.1
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2607171
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.419494ad
K7GWTrojan ( 005224381 )
Cybereasonmalicious.343847
BaiduWin32.Trojan.Kryptik.anp
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FZVO
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Hottrend.evdggu
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Llra
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
BitDefenderThetaGen:NN.ZexaF.34628.lr0@aif64ifi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionTrojan-FORL!A65E87834384
FireEyeGeneric.mg.a65e878343847902
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1125229
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Trojan/Win32.Zeroaccess.C264391
McAfeeTrojan-FORL!A65E87834384
MAXmalware (ai score=100)
VBA32BScope.TrojanProxy.Bunitu
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingRansom.Cerber!8.3058 (C64:YzY0OpjLGoIv0jzb)
YandexTrojan.Agent!DOmum8/7rV0
IkarusWin32.Karagany
FortinetW32/Dridex.DD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HgIASOQA

How to remove Win32/Kryptik.FZVO?

Win32/Kryptik.FZVO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment