Trojan

Should I remove “Trojan.Win64.Kryplod.pef”?

Malware Removal

The Trojan.Win64.Kryplod.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Kryplod.pef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Likely virus infection of existing system binary
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • Attempts to modify proxy settings

How to determine Trojan.Win64.Kryplod.pef?


File Info:

name: BCFA37FF8E4F4448854C.mlw
path: /opt/CAPEv2/storage/binaries/43f6c7128bd66d0c6c209be06f504d578a7816f18d9266aaeaa377b5f3828fd3
crc32: CA1D7C99
md5: bcfa37ff8e4f4448854ca44cee80b539
sha1: 37678e441ba4a3ef4bcc5b3810074a34bc790d84
sha256: 43f6c7128bd66d0c6c209be06f504d578a7816f18d9266aaeaa377b5f3828fd3
sha512: 23d75e4e0e1ff562d57e129a80a5d858f715975fac95005678365ebe306e1b0eba800ad3e1cc7c4753355143e027fb183021196471707886e12cf5220e4a2327
ssdeep: 24576:jKvyDZTRW8fdedsqjnhMgeiCl7G0nehbGZpbD:jKaDZT88fQDmg27RnWGj
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BC750211F78AC1B2DD6601724AEAE31CC46EB9614F314AD3E3DD6F1E9E700D19932B86
sha3_384: 2ecb17ef5e6cb05eef3dff682809d3eabadb435cb968777c623f2768a91ea1572824f1fa0b286628e168353824219def
ep_bytes: e84f030000e991feffffccff25f0a343
timestamp: 2016-10-28 07:53:26

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: LogTransport Application
FileVersion: 7.1.1.3403
InternalName: LogTransport2
LegalCopyright: Copyright 2008-15 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: LogTransport2.exe
PrivateBuild: 7.1.1.3403
ProductName: LogTransport Application
ProductVersion: 7.1.1.3403
Translation: 0x0409 0x04b0

Trojan.Win64.Kryplod.pef also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win64.Kryplod.4!c
Elasticmalicious (high confidence)
DrWebWin32.Expiro.153
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.bcfa37ff8e4f4448
McAfeeGenericRXRG-ID!BCFA37FF8E4F
CylanceUnsafe
SangforTrojan.Win64.Kryplod.pef
K7AntiVirusVirus ( 0058c9f71 )
K7GWVirus ( 0058c9f71 )
Cybereasonmalicious.41ba4a
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Expiro.NDO
TrendMicro-HouseCallTROJ_GEN.R002C0PB622
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win64.Kryplod.pef
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastFileRepMalware
TencentWin32.Virus.Expiro.Pkra
Ad-AwareWin32.Expiro.Gen.7
TrendMicroTROJ_GEN.R002C0PB622
McAfee-GW-EditionBehavesLike.Win32.Kudj.tm
EmsisoftWin32.Expiro.Gen.7 (B)
GDataWin32.Expiro.Gen.7
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASVirus.316
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.JO.R462994
Acronissuspicious
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
APEXMalicious
RisingVirus.Expiro!8.375 (CLOUD)
IkarusVirus.Win32.Expiro
FortinetW32/FileInfector.C!tr
AVGFileRepMalware
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win64.Kryplod.pef?

Trojan.Win64.Kryplod.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment