Malware

Win32/Kryptik.BLRW removal guide

Malware Removal

The Win32/Kryptik.BLRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BLRW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Bulgarian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Kryptik.BLRW?


File Info:

name: 52DA197C5FB00A4FF1D1.mlw
path: /opt/CAPEv2/storage/binaries/d6afc64df89d1f9d24dcab19e9a9ced3281c884e0e6270c56fee8a2157187252
crc32: 8B44ECF6
md5: 52da197c5fb00a4ff1d15b68b86d5192
sha1: 0baa667b12dc9b47f64c18bf82482f6143aafa6f
sha256: d6afc64df89d1f9d24dcab19e9a9ced3281c884e0e6270c56fee8a2157187252
sha512: b1d35183db042b799649700cd932810c38f8f4a57964c032520fbf2af7908184f7bb646c3a59c34f724c9158200e5c3789aba00d02c078c9bc3fd1f72e06a7ef
ssdeep: 6144:dktma6lw18W7n0txepvCTJvXvgsw/n2Uk9yOcKokTn5:2/18W7naTV/gswP2UuBokT5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB3401A0F1D06056D82F1C3766E6368F3A1D2D30C528DE09B83D6DAE66702F64DAD763
sha3_384: ed879c06028a0fa3059206ef73fb3b6c688a5f514f28021243cc8c4fe2e1923cffa045025074e77d2d840d739a1fcd8d
ep_bytes: 558bec81ec0801000056576a055e6a00
timestamp: 2004-07-08 12:04:04

Version Info:

0: [No Data]

Win32/Kryptik.BLRW also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.52da197c5fb00a4f
McAfeeGeneric-FANC!52DA197C5FB0
CylanceUnsafe
ZillyaTrojan.Fareit.Win32.4331
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.c5fb00
BitDefenderThetaGen:NN.ZexaF.34682.oy0@aWVoBAkI
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BLRW
TrendMicro-HouseCallTSPY_ZBOT.SMODA
KasperskyTrojan-PSW.Win32.Fareit.alpy
NANO-AntivirusVirus.Win32.Gen.ccmw
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan-QQPass.QQRob.Wimw
ComodoTrojWare.Win32.Kryptik.BNUE@54hcgb
DrWebTrojan.Carberp.1216
TrendMicroTSPY_ZBOT.SMODA
McAfee-GW-EditionGeneric-FANC!52DA197C5FB0
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
APEXMalicious
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.C5
KingsoftWin32.PSWTroj.Fareit.al.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.AKK
GoogleDetected
VBA32TrojanPSW.Fareit
MalwarebytesMalware.Heuristic.1003
RisingDownloader.Carberp!8.2EB (TFE:1:bDfNVrN1SeF)
YandexTrojan.Carberp!JbO+TexJGpc
IkarusTrojan-PWS.Win32.Fareit
FortinetW32/Fareit.ALPY!tr.pws
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.BLRW?

Win32/Kryptik.BLRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment