Malware

Win32/Kryptik.ADRV malicious file

Malware Removal

The Win32/Kryptik.ADRV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ADRV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.ADRV?


File Info:

name: 5D82C578FBF5FFCBA6B3.mlw
path: /opt/CAPEv2/storage/binaries/7618c78a067a0735c1ae770191bbaacc485b853bdf2ccfe473508989dc77b463
crc32: 7EA6D2B5
md5: 5d82c578fbf5ffcba6b35818fbfe405f
sha1: 2b63178b40207d478dc217183f4de496f71fde92
sha256: 7618c78a067a0735c1ae770191bbaacc485b853bdf2ccfe473508989dc77b463
sha512: 1e0e6751898b21ff335f87e196e081493819aaf5ca2be18c26392bd5d9e29c219a646e943791be0339fc8e8ee74509eff27203cc1a28f1932ecc67c828d2ce6f
ssdeep: 1536:zGZkbiz29mKGfvCtwZMtvNtHGqUcBsOxnWgMAKZStBdMLLrixeTnHPYTbOIjdn2i:yZkOz29bGfaHtHjUcPHMAq+wLr1vYTbf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14593F16973280D33F3580AF4FAA1B6334B21F2DA11F6C3577980C9C9A7743AB1851D45
sha3_384: 353e66804293c67fc893730b98a5a9000a4a0eb362fe361cae19e2166edfc460da61b7d151341978ef45ba0afcb3af2f
ep_bytes: 558bec81ecbc02000060892d58844100
timestamp: 2012-04-03 17:01:41

Version Info:

0: [No Data]

Win32/Kryptik.ADRV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.211147
ClamAVWin.Packed.Zbot-9758870-0
FireEyeGeneric.mg.5d82c578fbf5ffcb
CAT-QuickHealTrojan.Boaxxe.E
SkyhighBehavesLike.Win32.Downloader.nc
McAfeePWS-Zbot.gen.beu
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Zbot.Win32.59251
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0040ae601 )
AlibabaVirTool:Win32/Obfuscator.92bb60c3
K7GWSpyware ( 0040ae601 )
Cybereasonmalicious.b40207
BitDefenderThetaGen:NN.ZexaF.36744.fmX@amGBcNe
VirITTrojan.Win32.Multi.TG
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.ADRV
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.iu
BitDefenderGen:Variant.Lazy.211147
NANO-AntivirusTrojan.Win32.MlwGen.msqol
AvastWin32:Crypt-MGG [Trj]
TencentMalware.Win32.Gencirc.10b8edfb
SophosTroj/Agent-VSS
BaiduWin32.Adware.Kryptik.b
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PWS.Multi.500
VIPREGen:Variant.Lazy.211147
TrendMicroTROJ_REVETON.SMZ
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.211147 (B)
IkarusTrojan.Crypt
GDataGen:Variant.Lazy.211147
JiangminTrojan/Generic.zcng
WebrootW32.Infostealer.Zeus
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Packed]/Win32.Krap
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Kryptik.ADXK@4nyoqo
ArcabitTrojan.Lazy.D338CB
ZoneAlarmPacked.Win32.Krap.iu
MicrosoftPWS:Win32/Fareit
VaristW32/Zbot.EP.gen!Eldorado
AhnLab-V3Dropper/Win32.Injector.R23071
VBA32BScope.Malware-Cryptor.SB.01798
ALYacGen:Variant.Lazy.211147
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_REVETON.SMZ
RisingSpyware.Zbot!8.16B (TFE:2:AMPjydXaJrV)
YandexTrojan.GenAsa!JSFArLrSENY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Packed.Krap.iu
FortinetW32/ZBOT.HL!tr
AVGWin32:Crypt-MGG [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ADRV?

Win32/Kryptik.ADRV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment