Malware

Win32/Kryptik.ASCA.Gen information

Malware Removal

The Win32/Kryptik.ASCA.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ASCA.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Attempts to modify user notification settings

How to determine Win32/Kryptik.ASCA.Gen?


File Info:

name: 3C1C83BD5DCE4B4CCB6A.mlw
path: /opt/CAPEv2/storage/binaries/0e326b91c033d04d819c53a45e0db18456535f59fdac96f78cd23443f04fe9ab
crc32: 61FB263C
md5: 3c1c83bd5dce4b4ccb6a3147e6eee5af
sha1: 7346a49aca617d710fae7a96ccb530ad56fcb150
sha256: 0e326b91c033d04d819c53a45e0db18456535f59fdac96f78cd23443f04fe9ab
sha512: b74d1d4caf8555134bf01332d68a203e15ee442846a1a1e56c6848e02aa16d5937fa38c361ede947a44257106fe8a95fd4bfc56a175ac64d2fd0d1c67086fe45
ssdeep: 3072:7n6/HBq3qAdGhS4k5p5pU4T4B+jca8Wz/9DMFIW925pOLA/hmqVvTVLC4HTkweo/:7+Bq3qnop535+Wzmw5pSqpheLweu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F141321D7AEA77ACD4DCAB382F10F94DC40D977D07AE022EDF62A162B1931D2C554C6
sha3_384: db379050164d3e2375699601c1a635f6e8ca11056553d61c8d4f6feaddf7c5e0ac1aec15b544b6d39605409802f777b1
ep_bytes: 8d35e82f4000bf004040006a6459f3a4
timestamp: 2012-01-03 17:21:55

Version Info:

0: [No Data]

Win32/Kryptik.ASCA.Gen also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
tehtrisGeneric.Malware
ClamAVWin.Trojan.Agent-488303
CAT-QuickHealTrojan.Lethic.B
McAfeeBackDoor-FJW
CylanceUnsafe
VIPRETrojan.VIZ.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
AlibabaMalware:Win32/km_24e03.None
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.d5dce4
BaiduWin32.Trojan.Kryptik.ur
VirITTrojan.Win32.Zyx.RB
CyrenW32/FakeAlert.WP.gen!Eldorado
SymantecW32.Waledac.D!gen3
Elasticmalicious (high confidence)
ESET-NOD32Win32/Kryptik.ASCA.Gen
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Fakealert.crbauv
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:Downloader-SEE [Trj]
TencentWin32.Trojan.Generic.Ddhl
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.ARQC@4t65ce
DrWebTrojan.Fakealert.35771
ZillyaTrojan.FakeAV.Win32.254002
TrendMicroTSPY_FAREIT.SMKZ
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3c1c83bd5dce4b4c
SophosMal/Generic-R + Mal/Zbot-KR
IkarusTrojan-PSW.Win32.Tepfer
GDataTrojan.VIZ.Gen.1
JiangminTrojan/Tepfer.Gen
WebrootW32.Rogue.Gen
AviraTR/Injector.aiv
Antiy-AVLTrojan/Generic.ASMalwS.55
KingsoftWin32.Troj.Agent.a.(kcloud)
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
MicrosoftRogue:Win32/FakeRean
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R49042
Acronissuspicious
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=100)
VBA32Heur.Trojan.Hlux
MalwarebytesTrojan.LameShield
TrendMicro-HouseCallTSPY_FAREIT.SMKZ
RisingDownloader.Moure!8.628 (TFE:4:hdVWaL0EVQM)
YandexTrojan.GenAsa!IT5S7+0GiH8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
BitDefenderThetaGen:NN.ZexaF.34726.mqX@amcbFBjk
AVGWin32:Downloader-SEE [Trj]
PandaTrj/Tepfer.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ASCA.Gen?

Win32/Kryptik.ASCA.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment