Malware

Win32/Kryptik.ATRE removal

Malware Removal

The Win32/Kryptik.ATRE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ATRE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine Win32/Kryptik.ATRE?


File Info:

name: 1EEEFDAB0C4564291E2B.mlw
path: /opt/CAPEv2/storage/binaries/4babd9eb98c78e6372d36d9e1b09712fbe641cfd496e0b1408b816c0455dc483
crc32: 96914BE1
md5: 1eeefdab0c4564291e2b6b5a1adc538b
sha1: 09eda2dd1e1343f91fa2c48f11be95402f94ff0e
sha256: 4babd9eb98c78e6372d36d9e1b09712fbe641cfd496e0b1408b816c0455dc483
sha512: 4a179ba501f8f0a5e39d06a117f43e7484bf2989299f1b0026209f05f85bab4c45a5e55d2ddbdb8d94cdce56e1a2781b10dbc2c58cc43183a7ed902c537cd42c
ssdeep: 12288:PLy04RTDIXNyAHFfmogNUmiZiqK7/bU1SzCLtq3dLjkCoNUVsYyjXXUGqcJtAD/R:PMTA5moBzZiX7jUshoNU/wXkzcJq9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EF4336634A4F1B7E42BEA3422428A2557377DA159B40DFCB6DBB3A1A3331A7413F610
sha3_384: 50930b7529c7a600500ba168f79901bbfe4ada75e4355fb80746ddd3c5cfe4eeaa29ff95c8a7b12d92bf9157c456b2bf
ep_bytes: 8d3d1021400083c7928b37c1e6108d46
timestamp: 2012-12-30 18:37:06

Version Info:

0: [No Data]

Win32/Kryptik.ATRE also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
DrWebBackDoor.Slym.1425
MicroWorld-eScanGen:Heur.Honret.2
FireEyeGeneric.mg.1eeefdab0c456429
CAT-QuickHealTrojan.Urausy.C
McAfeeBackDoor-FJW
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.b0c456
ArcabitTrojan.Honret.2
BitDefenderThetaGen:NN.ZexaF.34592.WuW@aG262n
CyrenW32/SuspPack.EX.gen!Eldorado
SymantecTrojan.Ransomlock!g39
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ATRE
APEXMalicious
TrendMicro-HouseCallTROJ_FAKEAV.SMCC
ClamAVWin.Packed.Honret-9828988-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Honret.2
NANO-AntivirusTrojan.Win32.Slym.bgrzvp
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:LockScreen-SL [Trj]
TencentWin32.Init.QQRob.lso
Ad-AwareGen:Heur.Honret.2
EmsisoftGen:Heur.Honret.2 (B)
ComodoTrojWare.Win32.Kryptik.NEWJ@4tnq6z
VIPREGen:Heur.Honret.2
TrendMicroTROJ_FAKEAV.SMCC
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-KR
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Tepfer.Gen
GoogleDetected
AviraTR/Kryptik.EB.10
MAXmalware (ai score=81)
MicrosoftBackdoor:Win32/Kelihos.F
GDataGen:Heur.Honret.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R52297
VBA32Heur.Trojan.Hlux
ALYacGen:Heur.Honret.2
MalwarebytesGeneric.Rogue.Fake.DDS
RisingBackdoor.Kelihos!1.68F2 (CLASSIC)
YandexTrojan.GenAsa!h0a3Pgh2mx0
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.PSW.Tepfer.chmq
FortinetW32/Krypt.HAHA!tr
AVGWin32:LockScreen-SL [Trj]
PandaTrj/Ransom.AB
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.ATRE?

Win32/Kryptik.ATRE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment