Malware

About “Win32/Kryptik.AUOV” infection

Malware Removal

The Win32/Kryptik.AUOV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AUOV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings

How to determine Win32/Kryptik.AUOV?


File Info:

name: F8A203492376EB135933.mlw
path: /opt/CAPEv2/storage/binaries/9662eba1d3bd45a30da2518b15c40cc4446a231f8ba00cbcb4549153ebf2691d
crc32: 19197AEC
md5: f8a203492376eb1359330bf7c29cfa7a
sha1: 0c1bb7cc66dd44260ef09eccd9217772b9559dfe
sha256: 9662eba1d3bd45a30da2518b15c40cc4446a231f8ba00cbcb4549153ebf2691d
sha512: 69c7f2df11c8b2d64be1dcb50a9870fbcc8fcd8e581a081d37d881b20c02ba51c1a3b8c535697fb4375698d0c4a8b51733c458224b1dfe33ec695de5211566b2
ssdeep: 6144:1OaZ2XGsk8ZTwr9EXULAOSKCU9xRxkDMDHHckofpssnR1eTOSP0k:Xci9E0Alu9Vk4bfoKoeaSMk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A68423AAEAC43836C76BDCBE5530943DB30F8B976C1CA6479347A413E169EE06935C43
sha3_384: 18a51a80c247a1f76931a4c298ca08dd63bf1da33457208ce88bcfd6efdd3013659e44bf04f365789e7d78be96d9f643
ep_bytes: 681c2140005e83c6928b366a5659c1e6
timestamp: 2013-02-03 21:44:44

Version Info:

0: [No Data]

Win32/Kryptik.AUOV also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
tehtrisGeneric.Malware
DrWebTrojan.Fakealert.36624
MicroWorld-eScanGen:Heur.ARP.1
FireEyeGeneric.mg.f8a203492376eb13
CAT-QuickHealTrojan.Urausy.C
McAfeeBackDoor-FJW
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.92376e
BitDefenderThetaGen:NN.ZexaF.34698.yqW@ay8HDKoO
VirITTrojan.Win32.Generic.APS
CyrenW32/SuspPack.EX.gen!Eldorado
SymantecTrojan.Ransomlock!g39
Elasticmalicious (high confidence)
ESET-NOD32Win32/Kryptik.AUOV
APEXMalicious
ClamAVWin.Trojan.Zbot-9759961-0
KasperskyPacked.Win32.Katusha.y
BitDefenderGen:Heur.ARP.1
NANO-AntivirusTrojan.Win32.FakeAV.bjpunk
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:FakeAV-EKA [Trj]
RisingBackdoor.Kelihos!1.68F2 (CLASSIC)
Ad-AwareGen:Heur.ARP.1
TACHYONTrojan/W32.Katusha.399872.H
EmsisoftGen:Heur.ARP.1 (B)
ComodoTrojWare.Win32.Kryptik.AUOV@4ub47w
VIPREGen:Heur.ARP.1
TrendMicroTROJ_FAKEAV.SMCC
McAfee-GW-EditionBehavesLike.Win32.VirRansom.fc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-LR
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.ARP.1
JiangminTrojan/Tepfer.Gen
GoogleDetected
AviraTR/Rogue.mio
Antiy-AVLTrojan/Generic.ASMalwS.57
ZoneAlarmPacked.Win32.Katusha.y
MicrosoftRogue:Win32/Winwebsec
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R52731
VBA32Heur.Trojan.Hlux
ALYacGen:Heur.ARP.1
MAXmalware (ai score=89)
MalwarebytesTrojan.LameShield
TrendMicro-HouseCallTROJ_FAKEAV.SMCC
TencentWin32.Packed.Katusha.Gkjl
YandexTrojan.GenAsa!ApJwVLPONes
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.PSW.Tepfer.chmq
FortinetW32/Kryptik.X!tr
AVGWin32:FakeAV-EKA [Trj]
PandaTrj/Tepfer.B
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.AUOV?

Win32/Kryptik.AUOV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment