Malware

Troj/Kryptik-RR (file analysis)

Malware Removal

The Troj/Kryptik-RR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Kryptik-RR virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Troj/Kryptik-RR?


File Info:

name: B1EDCC81C12C42566B4F.mlw
path: /opt/CAPEv2/storage/binaries/b55fe46402878d4b2fac407ed7bf2f17d227bd6d4b037acb36bbd07ebc3fcd61
crc32: F4DCCB22
md5: b1edcc81c12c42566b4fbb4fa2b3af6e
sha1: 559b1f859275dcace4bc3885a934c6f63821e435
sha256: b55fe46402878d4b2fac407ed7bf2f17d227bd6d4b037acb36bbd07ebc3fcd61
sha512: 3bd499c8b11c19112ba9f8c46d10d651b4d2ed7cb13fe3151e586e4d7c9218a3685cc316cb4e73432948d5a08476cdcffdfec752e46d1cd6eed33d278db275fb
ssdeep: 3072:BfUaDdXWWusQymdFdapGhf0RyR1qPF/njjC6tQV1xVyLZ+UJdUhKxorMdcb56tpa:B/dmWcdRhf2yR1YxY1ryLgUJqhKirEBm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10404029FB99DA43AC1F3D17C4D110ABB263B658DFB398D46081DBD693DDEA72C299000
sha3_384: 8e2bb2ac1ba41e7185965e6c25475abdc2ab44ef89c5c3ee9a4ecc8d5182deb0535eef714153b4659e6b3685930dc659
ep_bytes: 60be00b044008dbe0060fbff5783cdff
timestamp: 2005-12-19 17:55:50

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Мастер переноса файлов и параметров
FileVersion: 5.1.2600.5512 (xpsp.080413-2105)
InternalName: MigWiz
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: MigWiz.Exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Troj/Kryptik-RR also known as:

BkavW32.MosquitoQKB.Fam.Trojan
LionicTrojan.Win32.Generic.lh2q
Elasticmalicious (moderate confidence)
DrWebTrojan.MulDrop1.64009
MicroWorld-eScanGen:Heur.VIZ.2
FireEyeGeneric.mg.b1edcc81c12c4256
ALYacGen:Heur.VIZ.2
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.216697
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojan:Win32/Kryptik.799f0742
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.1c12c4
ArcabitTrojan.VIZ.2
BitDefenderThetaGen:NN.ZexaF.36196.lm1@amvbDdgc
VirITWorm.Win32.Generic.GHY
CyrenW32/S-a84f9024!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.AutoRun.cxytjh
SUPERAntiSpywareHeur.Agent/Gen-StaticIcon
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Lebag.bhv
EmsisoftGen:Heur.VIZ.2 (B)
F-SecureHeuristic.HEUR/AGEN.1340728
BaiduWin32.Worm.Autorun.h
VIPREGen:Heur.VIZ.2
TrendMicroTROJ_GEN.R002C0DEP23
Trapminesuspicious.low.ml.score
SophosTroj/Kryptik-RR
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.bdhix
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1340728
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Lebag
XcitiumTrojWare.Win32.Lebeg.WJOD@5csyki
MicrosoftTrojan:Win32/Zbot.DSA!MTB
ViRobotTrojan.Win.Z.Viz.188825.BW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.VIZ.2
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
McAfeeGenericRXAA-AA!B1EDCC81C12C
TACHYONWorm/W32.AutoRun.188825
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.36680
TrendMicro-HouseCallTROJ_GEN.R002C0DEP23
RisingTrojan.Generic!8.C3 (CLOUD)
IkarusVirus.Win32.Virtob
FortinetW32/Generic.AC.1B437!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Kryptik-RR?

Troj/Kryptik-RR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment