Malware

Win32/Kryptik.BAAR information

Malware Removal

The Win32/Kryptik.BAAR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BAAR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BAAR?


File Info:

name: 7EBAE7F9E7D077285433.mlw
path: /opt/CAPEv2/storage/binaries/3bf8978f2b731107a596bf90ef684aba8058235640a6f6a2490cc76f7961dae4
crc32: 75D5D95A
md5: 7ebae7f9e7d077285433407b4ef3b140
sha1: acbcee1ab01d16015472e853bc1aa4a7ea4a9769
sha256: 3bf8978f2b731107a596bf90ef684aba8058235640a6f6a2490cc76f7961dae4
sha512: 1976693065d305d92e4b584a32fcaac098f1c3cdd11a929f9ae40d231fc50dd77d0aea088dcc18e26259b284278dfea6a5270159ab700ab0bdf3f321fca293f6
ssdeep: 6144:5lzoa7yNgAIQo8OLamr3RLyRnHhq92gkqnC2v7LA+Fq3PTzhV4:5tB7yNgD83m38E92TqC25sPPI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16874CF8E804DA095C03A4DB045C4EEFC85FDA2B7EBAC27DD3BA9DD06F789B42116594C
sha3_384: fd6508078ff3ee6480a01704041573a6df0447a810f23dd10c5e6e97b14600db1e66511d37b27c0ae10b3dadd2511435
ep_bytes: 558bec83ec508d45b050ff1534d04200
timestamp: 2013-05-02 17:02:26

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik.BAAR also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Lethic.Gen.11
FireEyeGeneric.mg.7ebae7f9e7d07728
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.fc
McAfeeDropper-FFI!7EBAE7F9E7D0
MalwarebytesGepys.Trojan.Dropper.DDS
VIPRETrojan.Lethic.Gen.11
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.9e7d07
BitDefenderThetaGen:NN.ZexaF.36802.wu3@a0ZWc5pc
VirITTrojan.Win32.Mods.AE
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BAAR
APEXMalicious
AvastWin32:Dropper-MRI [Drp]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Lethic.Gen.11
SophosTroj/Gepys-C
BaiduWin32.Trojan.Agent.eq
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Mods.1
ZillyaTrojan.Kryptik.Win32.4659382
Trapminemalicious.high.ml.score
EmsisoftTrojan.Lethic.Gen.11 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bpved
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Dropper]/Win32.Gepys
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Agent.rho@4x457v
ArcabitTrojan.Lethic.Gen.11
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE1.V68JXL
VaristW32/Agent.AZV.gen!Eldorado
AhnLab-V3Trojan/Win32.Zbot.R64039
Acronissuspicious
VBA32Trojan.ShipUp
ALYacTrojan.Lethic.Gen.11
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_AGENT_055399.TOMB
RisingDropper.Gepys!1.AEB3 (CLASSIC)
YandexTrojan.GenAsa!lLUyx8f5sz0
IkarusTrojan-Dropper.Win32.Gepys
FortinetW32/Zbot.FG!tr
AVGWin32:Dropper-MRI [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[dropper]:Multi/Gepys

How to remove Win32/Kryptik.BAAR?

Win32/Kryptik.BAAR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment