Malware

How to remove “Win32/Kryptik.ZNV”?

Malware Removal

The Win32/Kryptik.ZNV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ZNV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Win32/Kryptik.ZNV?


File Info:

name: E423C0C8301B6AE7F631.mlw
path: /opt/CAPEv2/storage/binaries/00e9077d8ced24788368e57bfef8d57c1ffafe584edddd090e8c088ef8b2801c
crc32: D0B67BC0
md5: e423c0c8301b6ae7f6316cc236efde07
sha1: 09e364d81ec457760076b96296a8ac007e12aca7
sha256: 00e9077d8ced24788368e57bfef8d57c1ffafe584edddd090e8c088ef8b2801c
sha512: 9f1564a3816fecc607ab88784b91caac489b3e3b1cac7e7c77ab018e964479a2e4e6ec292e7513c96ce8c5ccdda50f38ab50829001a4e23f3590818352b7a529
ssdeep: 3072:Kmvz/jAB2+bH2ZC2DhbQxwZSx3AICx3zU:1vP+Gv9bQxwwpPk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FA3E1388BF185B1E4BA3B7418B6CA421BB5FD80D9F9171E8195757F28723421A4AF23
sha3_384: 6dba9f900cd713bd570afef556102dd3e38f28aa7acf1094a567824e97e83fb12f9c51a82df1049d6764f24d7cf3de69
ep_bytes: 558bec6aff682801410068acec400064
timestamp: 2010-11-29 01:50:25

Version Info:

CompanyName: noneef Beaeby Ezag
FileDescription: reyrea, Abee Aalamiy L
FileVersion: 9.4.2100.3200
InternalName: Misuieva Bl
LegalCopyright: uecet tova 1994 - 2011
OriginalFilename: irin.exe
ProductName: Abhyhtpind
ProductVersion: 9.4.2100.3200
Translation: 0x0409 0x04b0

Win32/Kryptik.ZNV also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Dreidel.gm0@xKQrOZai
FireEyeGeneric.mg.e423c0c8301b6ae7
CAT-QuickHealTrojan.Rimecud.U
ALYacGen:Heur.Mint.Dreidel.gm0@xKQrOZai
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0040f0501 )
K7AntiVirusTrojan ( 0040f0501 )
CyrenW32/Rimecud.AB.gen!Eldorado
SymantecW32.Pilleuz!gen30
ESET-NOD32a variant of Win32/Kryptik.ZNV
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Worm.Win32.Generic
BitDefenderGen:Heur.Mint.Dreidel.gm0@xKQrOZai
NANO-AntivirusTrojan.Win32.Autoruner.klvqv
SUPERAntiSpywareTrojan.Agent/Gen-Crypted
AvastWin32:Carberp-RN [Trj]
TencentWin32.Trojan.Rimecud.Ahnv
Ad-AwareGen:Heur.Mint.Dreidel.gm0@xKQrOZai
SophosMal/Generic-R + Troj/HkMain-CT
ComodoTrojWare.Win32.Kryptik.RTTG@4m8ykb
DrWebTrojan.Packed.22480
ZillyaTrojan.Kryptik.Win32.212563
TrendMicroTROJ_RIMECUD.SMX
McAfee-GW-EditionPWS-Zbot.gen.aqo
EmsisoftGen:Heur.Mint.Dreidel.gm0@xKQrOZai (B)
IkarusTrojan.Win32.Rimecud
GDataGen:Heur.Mint.Dreidel.gm0@xKQrOZai
JiangminTrojan/Generic.usgo
WebrootW32.Malware.Heur
AviraTR/Crypt.EPACK.Gen8
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Rimecud.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.R20564
McAfeePWS-Zbot.gen.aqo
VBA32BScope.Worm.Palevo.2712
TrendMicro-HouseCallTROJ_RIMECUD.SMX
RisingTrojan.Win32.Generic.12D5ED4C (C64:YzY0Og2atsGL/0AG)
YandexTrojan.Kryptik!ZvebQdvRpQQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EQMA!tr
BitDefenderThetaGen:NN.ZexaF.34638.gm0@aKQrOZai
AVGWin32:Carberp-RN [Trj]
Cybereasonmalicious.8301b6
PandaTrj/Rimecud.f

How to remove Win32/Kryptik.ZNV?

Win32/Kryptik.ZNV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment