Malware

Win32/Kryptik.AWAQ removal instruction

Malware Removal

The Win32/Kryptik.AWAQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AWAQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win32/Kryptik.AWAQ?


File Info:

name: 0641FFD251BBCD3E1ECA.mlw
path: /opt/CAPEv2/storage/binaries/34e4fdcfe16a4b322de9539ff293f6c6eeba05ec17961fb5b5310165357e46cc
crc32: DA6AE728
md5: 0641ffd251bbcd3e1eca308e240163db
sha1: 0be3ba59b124aea6740c46a978a6001a9bde0095
sha256: 34e4fdcfe16a4b322de9539ff293f6c6eeba05ec17961fb5b5310165357e46cc
sha512: d8d418a0803d4f7991d1684332a4666096988589fb7f124f72f5b9a78a56f2f78243a525047f65a06683df2e2eadf8000308bcb57ce3658d04ac06babadab23c
ssdeep: 6144:KR4ZCK1pAaLKKH+zm10tg3gGM0L99fKAofDYgqvbx8txvBi2+Wn:Ka/nKKH+zm10CM0LzfWDNLi2+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198945A727152CC66C1100A70CD62D5FE69A57C9DCF22A0E7F2D67F4FB6B24E28870686
sha3_384: b95114ee9ef184c5d9a826f75b8ce89245dfb602dd61d27581252f0d3f89edb9075dea66ffbc2dcba84113725f572737
ep_bytes: 6a606890594500e8411e0000bf940000
timestamp: 2013-02-26 12:30:38

Version Info:

CompanyName: Section Old
FileDescription: sugar mount
FileVersion: 2.4.670.84
LegalCopyright: Copyright (c) 2011 Section Old. All rights reserved
ProductName: letter
ProductVersion: 2.4.670.84
OriginalFilename: letter.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.AWAQ also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Titirez.zq0@BWO5Rvci
FireEyeGeneric.mg.0641ffd251bbcd3e
McAfeePWS-Zbot.gen.any
VIPREGen:Heur.Mint.Titirez.zq0@BWO5Rvci
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Banker.RN
CyrenW32/A-73df760b!Eldorado
ESET-NOD32a variant of Win32/Kryptik.AWAQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Titirez.zq0@BWO5Rvci
NANO-AntivirusTrojan.Win32.Panda.cqujcd
AvastWin32:Dropper-gen [Drp]
TencentMalware.Win32.Gencirc.114949f6
Ad-AwareGen:Heur.Mint.Titirez.zq0@BWO5Rvci
SophosMal/Generic-S
ComodoTrojWare.Win32.Kryptik.tri@4vgah0
DrWebTrojan.PWS.Panda.3629
ZillyaTrojan.Zbot.Win32.106988
TrendMicroTROJ_SPNR.30GT13
McAfee-GW-EditionPWS-Zbot.gen.any
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Mint.Titirez.zq0@BWO5Rvci (B)
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Heur.Mint.Titirez.zq0@BWO5Rvci
JiangminTrojanSpy.Zbot.cvte
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.ZPACK.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.31
ArcabitTrojan.Mint.Titirez.E7E471
ViRobotTrojan.Win32.Zbot.409600.E
MicrosoftPWS:Win32/Zbot
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34698.zq0@aWO5Rvci
ALYacGen:Heur.Mint.Titirez.zq0@BWO5Rvci
MAXmalware (ai score=80)
VBA32BScope.Malware-Cryptor.Zbot.2113
TrendMicro-HouseCallTROJ_SPNR.30GT13
RisingTrojan.Kryptik!8.8 (TFE:5:7d5NVtInFlS)
YandexTrojanSpy.Zbot!8ZBM9LGN6TU
SentinelOneStatic AI – Suspicious PE
FortinetW32/Zbot.ATA!tr
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.251bbc
PandaTrj/OCJ.D

How to remove Win32/Kryptik.AWAQ?

Win32/Kryptik.AWAQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment