Malware

About “Win32/Kryptik.APE” infection

Malware Removal

The Win32/Kryptik.APE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.APE virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.APE?


File Info:

name: 93D52F1E2E853E15990A.mlw
path: /opt/CAPEv2/storage/binaries/20334d853ea77c284fc9a8e58c6b45788aa25701cd7df137ffe6ec8659ecdad6
crc32: B775B4D8
md5: 93d52f1e2e853e15990a5b543ed83a6d
sha1: 07f7d183d5f95dd12f99734c0d95aa98ca6f03f8
sha256: 20334d853ea77c284fc9a8e58c6b45788aa25701cd7df137ffe6ec8659ecdad6
sha512: 6fbc6de7515de012e9972d8e2f1f3615362775aff95d344249dc3b7d66aa4393c6695a0e43022c2094db80c53f52eab61f61c5cd906c45ae01fcbe2602a83df1
ssdeep: 12288:7rcs7bCcgdQS6PpV9zlbVdZHK32L/8H9DDg9kkezqgOUukFdC:F7+HdQS6Pf9bdZHKmLmD4LeehUuOC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAE423E1FE11BDB8F2A0417EDDF2D4A81E5B76A496698D1D8ADB084D483C0E3D639313
sha3_384: cebfed117a13023a3da3d330fc644079ed79796318c89de72f467c6142a4a69ad89e793926f20b489e16a5c1bcc328fa
ep_bytes: 54eb020fc989eeeb0aeb020fc989e6eb
timestamp: 2008-09-02 10:39:29

Version Info:

0: [No Data]

Win32/Kryptik.APE also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebTrojan.Packed.511
MicroWorld-eScanGen:Heur.Mint.Zard.25
FireEyeGeneric.mg.93d52f1e2e853e15
McAfeeGeneric PWS.kh
CylanceUnsafe
VIPREGen:Heur.Mint.Zard.25
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.e2e853
BitDefenderThetaAI:Packer.12E75BAE1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.APE
ClamAVWin.Trojan.Zbot-3668
KasperskyPacked.Win32.CPEX-based.dw
BitDefenderGen:Heur.Mint.Zard.25
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareGen:Heur.Mint.Zard.25
EmsisoftGen:Heur.Mint.Zard.25 (B)
ZillyaTrojan.Kryptik.Win32.1959
McAfee-GW-EditionBehavesLike.Win32.VirRansom.jc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Generic-E
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Zard.25
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.FC
MicrosoftVirTool:Win32/Bober.A
CynetMalicious (score: 100)
VBA32Trojan-Spy.Win32.Zbot.jek
ALYacGen:Heur.Mint.Zard.25
APEXMalicious
RisingTrojan.Spy.Win32.Zbot.fak (CLASSIC)
YandexTrojan.GenAsa!w4uHLGg92v0
IkarusTrojan.Win32.Crypt
FortinetW32/Zbot.EOW!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.APE?

Win32/Kryptik.APE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment