Malware

Win32/Kryptik.BLKB removal guide

Malware Removal

The Win32/Kryptik.BLKB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BLKB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BLKB?


File Info:

name: 975BA669A88C0B89669E.mlw
path: /opt/CAPEv2/storage/binaries/bba1a0a32b3a8dedec74e8e01b70479a35a7a87f0bb54c4c1cb69090eebb117a
crc32: 618273CE
md5: 975ba669a88c0b89669e6a547180e930
sha1: 04125601ffe4af1630837b7af714c0d6f1bed93b
sha256: bba1a0a32b3a8dedec74e8e01b70479a35a7a87f0bb54c4c1cb69090eebb117a
sha512: 118ed52c622cfbd7261e7f9c394b08b621b13b506323b297486271f355e58b7d72ff36506eb38affff3bd11bdf8095db75642dd315b4af73fe6fdb2e4a4f7c13
ssdeep: 384:9JBcQ3oQ/jeO6Rj2cKfbKyVRGqJ06Mj7XnHf4HCXk:BcqoGjeO6Rjnyzohv/4Hok
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FE243756A9339E3C12285717CE2A2F4845DEED8361FB28E644AF748137A64377408FB
sha3_384: ba4b6ef6ed2ba1c74ccd682696cc54e5113714ab8cdee1a76e9d4bddfe0b216247869b27fd86c7ca27b39442cd9c4348
ep_bytes: e80bfdffffe93ee4ffffcccccccccccc
timestamp: 2013-09-27 06:51:23

Version Info:

0: [No Data]

Win32/Kryptik.BLKB also known as:

BkavW32.FamVT.GeND.Trojan
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Downloader.Upatre-5744087-0
FireEyeGeneric.mg.975ba669a88c0b89
SkyhighBehavesLike.Win32.Generic.nm
McAfeeDownloader-FTL!975BA669A88C
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
K7GWTrojan-Downloader ( 0055c6c71 )
Cybereasonmalicious.1ffe4a
ArcabitTrojan.Ppatre.Gen.1
BaiduWin32.Trojan-Downloader.Small.cl
VirITTrojan.Win32.Zbot.CIP
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BLKB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Bublik.bgbm
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Bublik.cixlrg
SUPERAntiSpywareTrojan.Agent/Gen-Email
AvastWin32:Kryptik-MYH [Trj]
TencentTrojan.Win32.Bublik.hl
SophosTroj/Agent-ADVQ
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
EmsisoftTrojan.Ppatre.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Bublik.gaz
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUB@5s5ra0
MicrosoftPWS:Win32/Zbot!atmnm
ZoneAlarmTrojan.Win32.Bublik.bgbm
GDataWin32.Trojan.PSE.10565N
VaristW32/Kryptik.LQX.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.R83776
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.cqX@amHqosdi
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=88)
VBA32Trojan.Downloader.3913
Cylanceunsafe
ZonerTrojan.Win32.19835
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!p6di0RnSt04
IkarusBackdoor.Win32.Androm
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.AAB!tr
AVGWin32:Kryptik-MYH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.BLKB?

Win32/Kryptik.BLKB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment