Malware

Win32/Kryptik.ABRW removal

Malware Removal

The Win32/Kryptik.ABRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ABRW virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.ABRW?


File Info:

name: EA6C86C8BFF237B4B2A8.mlw
path: /opt/CAPEv2/storage/binaries/73a46056099116790dd960f5dd3f249bd9b380bf5835b5b6718731f4936aec11
crc32: E74F8A17
md5: ea6c86c8bff237b4b2a875d7c76732e9
sha1: 9c9171d3f9a9d4f7703f4a0d8500cdb17ac092e1
sha256: 73a46056099116790dd960f5dd3f249bd9b380bf5835b5b6718731f4936aec11
sha512: 929f41395279b53e1f7f2e82094a0a6f6497091100ce1a3871a1cde8439ede9de303b4bf78b6f63536f04708ff6167771f46878de4747c4ca084ee21ce185616
ssdeep: 3072:FlCCGsYfNqu+f9/vIBkuUnJNMAMWO7Ze4GWGTnnY6V4WfwPuuwtiO+:/iquA/ubUnVMWOxGWGTnY6Omf9+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E624CFDB60325563C024A178D73288E789DBFB399F99A5290D0FAC59FA118E03B3FC55
sha3_384: 4cc849f96279b4eca3dcb46e0755f3809f332b7140ad071dd9f0b8c55f6f1aa50a8abc612971c4d92976117a4c216b65
ep_bytes: 8b055689430025000000a58905728943
timestamp: 2011-07-13 14:46:44

Version Info:

CompanyName: Promise Technology, Inc.
FileDescription: Coal Kudos Slate
FileVersion: 1.10
InternalName: Aloha Rolls Blown
OriginalFilename: Ftufdgibk.exe
ProductName: Tow
ProductVersion: 1.10
Translation: 0x0409 0x04b0

Win32/Kryptik.ABRW also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Bot.149655
FireEyeGeneric.mg.ea6c86c8bff237b4
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacBackdoor.Bot.149655
CylanceUnsafe
VIPRELookslike.Win32.Sirefef.zh (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 003633e11 )
AlibabaTrojan:Win32/Kryptik.85aa12e5
K7GWTrojan ( 003633e11 )
Cybereasonmalicious.8bff23
CyrenW32/Symmi.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ABRW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Bot.149655
NANO-AntivirusTrojan.Win32.Zbot.bjqmjz
SUPERAntiSpywareTrojan.Agent/Gen-Faldesc[Cont]
TencentMalware.Win32.Gencirc.10c0f80a
Ad-AwareBackdoor.Bot.149655
EmsisoftBackdoor.Bot.149655 (B)
ComodoMalware@#3o8iqvwo9l9if
ZillyaTrojan.Kryptik.Win32.889067
TrendMicroTROJ_KRYPTIK_FE2502CE.UVPM
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Reveton
GDataBackdoor.Bot.149655
JiangminTrojan.Generic.zzqy
WebrootW32.Bot.Gen
AviraTR/Zbot.J
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitBackdoor.Bot.D24897
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!ac
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1845999
Acronissuspicious
McAfeeGenericR-HMD!EA6C86C8BFF2
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.1722719767
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_KRYPTIK_FE2502CE.UVPM
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!T4zR9iSR+j4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ABC!tr
BitDefenderThetaGen:NN.ZexaF.34212.ny1@aupxvabi
AVGWin32:Reveton-Y [Trj]
AvastWin32:Reveton-Y [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ABRW?

Win32/Kryptik.ABRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment