Malware

Win32/Kryptik.AVUU removal guide

Malware Removal

The Win32/Kryptik.AVUU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AVUU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.AVUU?


File Info:

name: 5359BEE26A2109520111.mlw
path: /opt/CAPEv2/storage/binaries/79b3ffa31100db7179f86b5a535b8dae5f5f40513d2b481baf0d72a2c3895d7b
crc32: 28250DC1
md5: 5359bee26a21095201115713ac6a3b83
sha1: 074b59c580c03a913129b469be9c1ed06e236bf9
sha256: 79b3ffa31100db7179f86b5a535b8dae5f5f40513d2b481baf0d72a2c3895d7b
sha512: 011cb0a3eb3b7478cb07bb2a2b0a223d63a66d07d6e9f87cf24ad7a08518696e65da74a07183bc23b1186839de348e9e7ce9719fbf3860907daac65893552bb7
ssdeep: 3072:Dglj4xWJV52FQ1MaO/AFCxtCkBR5KQRgb9aiHJO380r/sQ1u7KAxFm4HMakv5ZUe:DDWhZ1LO4eqQRg5dHJO3JrUQ1gTxFm44
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162041255A6C86448C4B7883918EE713F192CB44D30A49FFD7A64B502F986728BD06F9B
sha3_384: 1e6525e20006436db6fd19c167d4a706a410551b82e657a459f14c0cc66763b0ee2d7130641c1d3c3811f522b91bd49c
ep_bytes: 60be004042008dbe00d0fdff5789e58d
timestamp: 2011-01-10 17:02:38

Version Info:

CompanyName: Mach5 Software
FileDescription: Goad Mid Zips
FileVersion: 9.2
InternalName: Tipsy Aged Nag
LegalCopyright: Hrh 1998-2009
OriginalFilename: Meow.exe
ProductName: Zig
ProductVersion: 9.2
Translation: 0x0409 0x04b0

Win32/Kryptik.AVUU also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.45700798
FireEyeGeneric.mg.5359bee26a210952
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacTrojan.GenericKD.45700798
CylanceUnsafe
K7AntiVirusTrojan ( 0035c0fe1 )
K7GWTrojan ( 0035c0fe1 )
Cybereasonmalicious.26a210
VirITTrojan.Win32.Cryptor.A
CyrenW32/Zbot.DP.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AVUU
APEXMalicious
ClamAVWin.Trojan.Zbot-18571
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.45700798
NANO-AntivirusTrojan.Win32.Kryptik.bfgupf
SUPERAntiSpywareTrojan.Agent/Gen-Faker[desc]
AvastWin32:Zbot-NYU [Trj]
TencentWin32.Trojan.Jorik.bfor
Ad-AwareTrojan.GenericKD.45700798
EmsisoftTrojan.GenericKD.45700798 (B)
ComodoMalware@#3a89iq4tnszpa
DrWebTrojan.PWS.Panda.655
ZillyaTrojan.Jorik.Win32.54898
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/ZBot-BLO
IkarusTrojan.Crypt
JiangminTrojan/Menti.vel
AviraTR/Spy.Zbot.ZL
MAXmalware (ai score=89)
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.Generic.D2B956BE
ViRobotTrojan.Win32.A.Menti.187535
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.45700798
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R20682
McAfeePWS-Zbot.gen.ru
VBA32Trojan.Zbot
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!h17tDbLCWrQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ABC!tr
BitDefenderThetaGen:NN.ZexaF.34742.lm1@aeGRdToi
AVGWin32:Zbot-NYU [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.AVUU?

Win32/Kryptik.AVUU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment