Malware

About “Win32/Kryptik.BFRV” infection

Malware Removal

The Win32/Kryptik.BFRV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BFRV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.BFRV?


File Info:

name: 5B02DD66038D842D935B.mlw
path: /opt/CAPEv2/storage/binaries/19b549a8bd5a29b1cd7d16922899ba5688cf63a85d3f24e83525d1eecb6b7c69
crc32: 2E21733A
md5: 5b02dd66038d842d935b532e1f89aaec
sha1: 93f0f321c18819c3a4bd868084c7bde0ef181855
sha256: 19b549a8bd5a29b1cd7d16922899ba5688cf63a85d3f24e83525d1eecb6b7c69
sha512: 0f13b823ce0207a83233aa8dff7eec06d41067ee870d3ad46469e37492b056f00c6524842c4093aabb91ac649435316aa802da94aacd3ef191324aef027a934e
ssdeep: 6144:J80ej/BuzrDXP3PHBfP3HLp3PH4rBVfseGJfJclr7hL7N8gyUXJxZAA+4VcDmlYb:J81j5uzrD/3PHBfP3HLp3PH4bfCfivLM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA54010BE6E84E51FD30ED31421B2A7F0DCA9F264497EA7A3FD681874DB15B60273290
sha3_384: 930e7cf480ce41547e0d953f2f72c0ebec273a946bc2a4edff723bf650c6e17b6122c3a0db975875488227a74b39dc3b
ep_bytes: 6a015f4f8b356020400068b4244000a1
timestamp: 2003-11-13 23:15:40

Version Info:

0: [No Data]

Win32/Kryptik.BFRV also known as:

LionicHacktool.Win32.Katusha.3!c
tehtrisGeneric.Malware
DrWebTrojan.Packed.24465
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.5b02dd66038d842d
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.VIZ.Gen.1
Cylanceunsafe
VIPRETrojan.VIZ.Gen.1
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_28ffe9.None
K7GWTrojan ( 0040f5371 )
K7AntiVirusTrojan ( 0040f5371 )
BitDefenderThetaGen:NN.ZexaF.36132.smW@aGEApqfe
CyrenW32/Agent.VY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BFRV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Tepfer-61
KasperskyPacked.Win32.Katusha.aa
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Katusha.jucjqh
TencentMalware.Win32.Gencirc.116da38b
F-SecureTrojan.TR/Urausy.EB.14
BaiduWin32.Trojan.Kryptik.du
ZillyaTrojan.Kryptik.Win32.3985807
TrendMicroTROJ_KRYPTK.SMN5
Trapminemalicious.high.ml.score
SophosTroj/Agent-ACSF
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.dywu
AviraTR/Urausy.EB.14
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
XcitiumTrojWare.Win32.Kryptik.FRV@4zfejq
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmPacked.Win32.Katusha.aa
GDataTrojan.VIZ.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R74365
VBA32Malware-Cryptor.Hlux
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMN5
RisingBackdoor.Agent!1.9CE1 (CLASSIC)
YandexTrojan.GenAsa!Y47jcWPN6UQ
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.7177271.susgen
FortinetW32/Kryptik.BDPK!tr
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.BFRV?

Win32/Kryptik.BFRV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment