Trojan

Trojan:Win32/Cryware.B (file analysis)

Malware Removal

The Trojan:Win32/Cryware.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cryware.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Cryware.B?


File Info:

name: BFE31188F18F0274B63C.mlw
path: /opt/CAPEv2/storage/binaries/62ade19e0166db77ea4990f2ef2a88a1316c79e823c8ad6ac303e171bb7c116c
crc32: 354777CA
md5: bfe31188f18f0274b63ce9bafa3423c3
sha1: 90f46afcb671c626de284e3bcf1c163e9e35eece
sha256: 62ade19e0166db77ea4990f2ef2a88a1316c79e823c8ad6ac303e171bb7c116c
sha512: 430d0a2d7db88fb48510a383e4bd795b71026754fa172e4887502f4733534c5c9f2e09dd0dd4237200020f2baccd4c938c3500e3acda0518a8b90d9fed954e41
ssdeep: 6144:CFuTugRRtfS+k1MnYfJ8fS+AgBGo+UAOB+DgGmi72jEcTCTQMdlbi:CQTugntfS+k1MnYDo+UOgGmitcMlbi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13F84BF01B592C0B2D57108751DE8EBB15F3EBC554B30C9EB6BD807AA8F303D2A97497A
sha3_384: b42b1131a93a1f3e135f0891440e22e220f138a0c3a28b263eb052ffdf149c8acd46892aeaeb8382a79213d44bbc681c
ep_bytes: e8b1050000e974feffff558bec8b4508
timestamp: 2022-08-05 11:58:06

Version Info:

0: [No Data]

Trojan:Win32/Cryware.B also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.230802
FireEyeGeneric.mg.bfe31188f18f0274
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaE.34582.xqY@ay18fmi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQJN
KasperskyVHO:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Lazy.230802
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Variant.Lazy.230802
EmsisoftGen:Variant.Lazy.230802 (B)
VIPREGen:Variant.Fugrafa.262205
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Lazy.230802
JiangminBackdoor.Bladabindi.ij
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Cryware.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R509444
ALYacGen:Variant.Lazy.230802
MalwarebytesSpyware.Stealer
APEXMalicious
RisingStealer.Agent!8.C2 (TFE:dGZlOgW4YsvmCFE9wA)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FYKG!tr
AVGWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Cryware.B?

Trojan:Win32/Cryware.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment