Malware

Should I remove “Win32/Kryptik_AGen.CFN”?

Malware Removal

The Win32/Kryptik_AGen.CFN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.CFN virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik_AGen.CFN?


File Info:

name: F7A69B418BE983F69139.mlw
path: /opt/CAPEv2/storage/binaries/a96c86be42662ae46fa966d856de42a4a9f055c43c3da1e4888c4b2b3dfe9510
crc32: DA992AE4
md5: f7a69b418be983f691395f8445651785
sha1: c87667743eec881c98f4beb87fa38bb83dda661e
sha256: a96c86be42662ae46fa966d856de42a4a9f055c43c3da1e4888c4b2b3dfe9510
sha512: 2fe3e7e73d3e257fede64081ec65fc8750e69e188c983e3027e3f76fae8cf02c2c130e6703873fbcd6e904d3098ded3d47da854d77cb8258607ac35d81c04016
ssdeep: 98304:nvqLP1aRXY52YcS28RAzFwyxL/I8aern5LxDTQihsWS0+s3WHWlK4NR:v7ykYcCyxL/cer5LxDTQiS0+sm2lKc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C54613334264218DD1F5CC3D8D37FEE4B3FA839A8A40E87469A7E9C62416CD5E313996
sha3_384: c1e210355f2d765f69d38a4109b6c8a72d7995c4328e1b31f254342de0673d574fc76a94ba4294df3a4764f0de83e026
ep_bytes: 15151515151515151515151515151515
timestamp: 2013-08-16 04:15:04

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik_AGen.CFN also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.Ransom.Cerber.1
ClamAVWin.Packed.Fugrafa-10002548-0
FireEyeGeneric.mg.f7a69b418be983f6
McAfeePacked-AM!F7A69B418BE9
Cylanceunsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.43eec8
BitDefenderThetaGen:NN.ZexaE.36662.@R1@auvISqbc
CyrenW32/Zbot.ACQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.CFN
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderTrojan.Ransom.Cerber.1
AvastWin32:Kryptik-MRZ [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftTrojan.Ransom.Cerber.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Kryptik.ac
VIPRETrojan.Ransom.Cerber.1
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tc
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Crypt
GDataTrojan.Ransom.Cerber.1
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
MicrosoftTrojan:Win32/Gepys.DSB!MTB
GoogleDetected
ALYacTrojan.Ransom.Cerber.1
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Kryptik!1.A949 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Kryptik-MRZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik_AGen.CFN?

Win32/Kryptik_AGen.CFN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment