Malware

Win32/Kryptik.ANLB (file analysis)

Malware Removal

The Win32/Kryptik.ANLB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ANLB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.ANLB?


File Info:

name: D40BB900B57E87AEF256.mlw
path: /opt/CAPEv2/storage/binaries/35a8c85be2a4bf30292c93eb0990bf6423bae78fb25f809fef4e73651a42ac71
crc32: 44D0EC34
md5: d40bb900b57e87aef25698f0f8d709cc
sha1: 40f13b79578a96bc77ea2fd7811fb93b55468107
sha256: 35a8c85be2a4bf30292c93eb0990bf6423bae78fb25f809fef4e73651a42ac71
sha512: c47d0afb1aa634a1a8fd8220f11f47b5a3754b40ff5d7069a70f809345c6e9c22afe2add76e9a07a328dd2faab7cb11c50a932b37ddf51fffa663016f65dcfa1
ssdeep: 24576:NOPSeVmQY6LGFt6s1z7aqZwkzsxuegBn:UEWGFtBzmibEmn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101F42340FF2D729EDA110838C2435EC62BB0766FCDD407E715ED6B2A95229F4859F60B
sha3_384: 93d17969b56c4e70c0ab292d958de2f5ad865ab3a389d7be904f101f264c854c0030cba0149895d21ae224faad08a403
ep_bytes: 6affff0424810c24003040000fb70d9a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik.ANLB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lmka
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.VIZ.Gen.1
Cylanceunsafe
VIPRETrojan.VIZ.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040797b1 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.0b57e8
BaiduWin32.Trojan.Kryptik.zs
VirITTrojan.Win32.FakeAV_s.NC
CyrenW32/FakeAlert.VZ.gen!Eldorado
SymantecSecShieldFraud!gen10
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ANLB
APEXMalicious
KasperskyTrojan-PSW.Win32.Tepfer.bjga
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Slym.barfpm
ViRobotTrojan.Win32.Z.Tepfer.788992.D
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:FakeAlert-DAA [Trj]
TencentMalware.Win32.Gencirc.13be04c1
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureTrojan.TR/Winwebsec.gnnaou
DrWebBackDoor.Slym.825
ZillyaTrojan.Tepfer.Win32.11512
TrendMicroBKDR_KELIHOS.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d40bb900b57e87ae
SophosTroj/FakeAV-FWY
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Tepfer.Gen
WebrootW32.Trojan.Gen
AviraTR/Winwebsec.gnnaou
Antiy-AVLTrojan/Win32.Kryptik
XcitiumTrojWare.Win32.Kryptik.XXL@4rfof4
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-RogueAV
ZoneAlarmTrojan-PSW.Win32.Tepfer.bjga
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R40605
Acronissuspicious
McAfeeFakeAV-SecurityTool.fz
MAXmalware (ai score=99)
VBA32Trojan.FakeAV.01657
MalwarebytesTrojan.LameShield
PandaAdware/SystemTool
TrendMicro-HouseCallBKDR_KELIHOS.SM
RisingRogue.Winwebsec!8.B21 (TFE:2:IZQcUVDdnFG)
YandexTrojan.GenAsa!/1sLuhlP+jE
IkarusTrojan-PWS.Win32.Tepfer
MaxSecureTrojan.Malware.4710814.susgen
FortinetW32/FakeAlert.B!tr
BitDefenderThetaGen:NN.ZexaF.36250.WqW@amAs3fik
AVGWin32:FakeAlert-DAA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ANLB?

Win32/Kryptik.ANLB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment