Ransom

Ransom.Kryptik.2 removal

Malware Removal

The Ransom.Kryptik.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Kryptik.2 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Attempted to write to a harddisk volume
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Finnish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Ransom.Kryptik.2?


File Info:

name: 60EA4EAE8768B4338C12.mlw
path: /opt/CAPEv2/storage/binaries/0acf1362cfbd05345ca7fc6d7dcaac570aa37a87b88de7a4cd640b60b8f411ef
crc32: 3E17B2D8
md5: 60ea4eae8768b4338c12400081259163
sha1: 0b3f6ea68cccaaa716b25a3d964cbbce0eafae4f
sha256: 0acf1362cfbd05345ca7fc6d7dcaac570aa37a87b88de7a4cd640b60b8f411ef
sha512: e403b4687161253be34dba2da4cbe09f2434c40b37fc2c3f81b91e6597401a31bcb3ca3057309ada61564d37d003ac1d5b3adbab5b7438d995948a058b6dfb95
ssdeep: 3072://ccQajSbq2aaMZy0nBiHNxzurC7+DO6ARzoyF:/3QJ8aPxiQU3Mky
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA44E03AE06DC383F98E0FB4D271621FFD93A4D55215868FBA80B8E0DFCB49854159E2
sha3_384: 4555072faa1e9746b69dd2d9f5771177c5c991805087a5e421c3a91f42ae1fb14293eea99c0f7b6fa4e7b44e8743c4bf
ep_bytes: 558bec83ec78c745f480000000c745f0
timestamp: 2013-09-03 18:03:23

Version Info:

InternalName: RegNow Download Manager

Ransom.Kryptik.2 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Kryptik.2
FireEyeGeneric.mg.60ea4eae8768b433
CAT-QuickHealTrojan.Sirefef.A
ALYacGen:Variant.Ransom.Kryptik.2
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
K7GWTrojan ( 005110401 )
Cybereasonmalicious.e8768b
BitDefenderThetaGen:NN.ZexaF.34646.qW0@a49BoBdO
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BJOO
TrendMicro-HouseCallPossible_MALSTRC
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1251927
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Kryptik.2
NANO-AntivirusTrojan.Win32.ZAccess.cvizzf
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Sirefef
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Ransom.Kryptik.2
EmsisoftGen:Variant.Ransom.Kryptik.2 (B)
ComodoTrojWare.Win32.Sirefef.EB@52gts2
DrWebBackDoor.Maxplus.13077
VIPREGen:Variant.Ransom.Kryptik.2
TrendMicroPossible_MALSTRC
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Agent-ADLI
APEXMalicious
GDataGen:Variant.Ransom.Kryptik.2
JiangminBackdoor/ZAccess.omg
WebrootTrojan.Dropper.Gen
AviraTR/Sirefef.EB.2
MAXmalware (ai score=87)
KingsoftWin32.Hack.ZAccess.dj.(kcloud)
ArcabitTrojan.Ransom.Kryptik.2
MicrosoftTrojan:Win32/Sirefef.P
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R77271
McAfeeZeroAccess-FBR!60EA4EAE8768
VBA32Backdoor.ZAccess
MalwarebytesMalware.Heuristic.1001
RisingMalware.XPACK!1.9816 (CLASSIC)
YandexTrojan.GenAsa!GxREPXS0r4k
IkarusTrojan.Crypt2
FortinetW32/GenCBL.ADW!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.Kryptik.2?

Ransom.Kryptik.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment