Malware

Win32/Kryptik.AVIR removal tips

Malware Removal

The Win32/Kryptik.AVIR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AVIR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Kryptik.AVIR?


File Info:

name: 123DDD195E5E4FE2D0F8.mlw
path: /opt/CAPEv2/storage/binaries/9a73b3967ffd2f713dba4e2f13e7cf7dc0b979f29d405811ef48c8bca8487658
crc32: C95FD5BF
md5: 123ddd195e5e4fe2d0f8e4e8279d5a37
sha1: 0b340e1280dfce01095b50a395dc5c358213d71d
sha256: 9a73b3967ffd2f713dba4e2f13e7cf7dc0b979f29d405811ef48c8bca8487658
sha512: dbbcaf304b41f72f58de7c606f13d7544d846f050bfe80f2cfffd8c5f87ceb898256c1df81f4b1ec43971882dcd1aed2ee4525b6d16bca8c990f09871d9ad458
ssdeep: 3072:doY+1SiA4t45ZpHdcWfCOcGHrHvdAcV5GWx4AdyMk/ftPQXC9fUkcSZcmrqMYWq:cMRdRRHzBl4XMQn8uZr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193F3AE647202C022D93C5AF0C95ED4F642B57DA6CB04A1EBB2C5FF7B39B29A60536934
sha3_384: afde4d5510ee97e3f0525d6543fbb4748ac0cb8c78093e7c9b117517485ee9a95178378eca609873cc095fea36718f6c
ep_bytes: 558bec6aff682c914100687e2a400064
timestamp: 2009-05-30 12:32:39

Version Info:

CompanyName: Trend Micro
FileDescription: Trend Micro AntiVirus Plus AntiSpyware
FileVersion: 18.40.0.1301
InternalName: 7zsfx.exe
LegalCopyright: Copyright (C) 1995-2008 Trend Micro Incorporated. All rights reserved.
LegalTrademarks: Copyright (C) Trend Micro Inc.
OriginalFilename: 8lox.exe
PrivateBuild: Build 1400 - 8/27/2008
ProductName: Trend Micro Internet Security
ProductVersion: 18.40
SpecialBuild: 1301
Translation: 0x0409 0x04e4

Win32/Kryptik.AVIR also known as:

BkavW32.MassiveUsbM.Worm
LionicWorm.Win32.Palevo.r!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.15988
FireEyeGeneric.mg.123ddd195e5e4fe2
CAT-QuickHealTrojan.Rimecud.AA
ALYacGen:Variant.Symmi.15988
MalwarebytesTrojan.Rimecud
VIPREGen:Variant.Symmi.15988
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f5bf1 )
K7GWTrojan ( 0040f5bf1 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/A-07e67c59!Eldorado
SymantecW32.Pilleuz!gen37
ESET-NOD32a variant of Win32/Kryptik.AVIR
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.15988
NANO-AntivirusTrojan.Win32.Palevo.bksnpk
SUPERAntiSpywareTrojan.Agent/Gen-Rimecud
AvastWin32:MalPack-F [Trj]
TencentWin32.Trojan.Generic.Pnkl
Ad-AwareGen:Variant.Symmi.15988
EmsisoftGen:Variant.Symmi.15988 (B)
ComodoTrojWare.Win32.Zbot.JHMN@4x5rpp
DrWebWin32.HLLW.Autoruner.44048
TrendMicroTROJ_RIMECUD.SMN
McAfee-GW-EditionW32/Worm-FFJ!123DDD195E5E
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminWorm/Palevo.dfbh
WebrootW32.Infostealer.Zeus
GoogleDetected
AviraTR/Crypt.EPACK.Gen8
MAXmalware (ai score=82)
KingsoftWorm.Palevo.gv.(kcloud)
MicrosoftTrojan:Win32/Rimecud.A
GDataGen:Variant.Symmi.15988
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.R43586
McAfeeW32/Worm-FFJ!123DDD195E5E
VBA32BScope.Trojan.Tiggre
CylanceUnsafe
TrendMicro-HouseCallTROJ_RIMECUD.SMN
RisingMalware.Undefined!8.C (TFE:1:Wgs79iUQSXS)
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EQMA!tr
BitDefenderThetaGen:NN.ZexaF.34646.kq0@ams1bNai
AVGWin32:MalPack-F [Trj]
Cybereasonmalicious.95e5e4
PandaGeneric Malware

How to remove Win32/Kryptik.AVIR?

Win32/Kryptik.AVIR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment