Malware

Win32/Kryptik.BTEZ information

Malware Removal

The Win32/Kryptik.BTEZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BTEZ virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BTEZ?


File Info:

name: 8F96E0885143D3CC23CA.mlw
path: /opt/CAPEv2/storage/binaries/58c188cf4885876225f935ea93e8be95d597ea574387cdce1fbf4e511f6f6249
crc32: 795763B7
md5: 8f96e0885143d3cc23ca4938447b315f
sha1: bbab88d8caa23bf00348ad38c9d9cf04b8127c47
sha256: 58c188cf4885876225f935ea93e8be95d597ea574387cdce1fbf4e511f6f6249
sha512: 9a5aec22a1c9766ec5771ae00e879979bb944a633279db8afe47b30b7231c6d0704b7e36646c67e78b06e2f9134dffbaad622a462cfdaf61b6cdc842e9c0ae2e
ssdeep: 384:6DsjDGY2HXgrkhLZUgch1A9NB/erx0U6UvsaIapwvduzSof1wJjcU+W:keDG5H8y6gs1lxHNauzbfIcUp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BE24EB46FC50AB1D737C6B985F3A5F7A423F02A7856491C4092EB065E13F42A8D2D8F
sha3_384: 0533ad0a0c3ffbca595b35e29725d1d99430497e8b7cce5392043dc4c609929598dbbe2600f27a31c2fb93bc2dc84675
ep_bytes: 558bec6aff682823500068f01e500064
timestamp: 2014-01-16 08:59:27

Version Info:

0: [No Data]

Win32/Kryptik.BTEZ also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.Generic.m01v
CynetMalicious (score: 100)
FireEyeGeneric.mg.8f96e0885143d3cc
CAT-QuickHealTrojanpws.Zbot.28739
SkyhighBehavesLike.Win32.PWSZbot.nm
ALYacTrojan.Upatre.Gen.3
Cylanceunsafe
ZillyaTrojan.Bublik.Win32.30958
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
AlibabaTrojanDownloader:Win32/Bublik.2a18269f
K7GWTrojan-Downloader ( 0055c6c71 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.BUKE
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BTEZ
APEXMalicious
ClamAVWin.Malware.Upatre-9939730-0
KasperskyTrojan.Win32.Bublik.burd
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.DownLoad3.csplaw
MicroWorld-eScanTrojan.Upatre.Gen.3
AvastWin32:Agent-AUID [Trj]
TencentTrojan.Win32.Bublik.burh
TACHYONTrojan/W32.Bublik.33380.B
EmsisoftTrojan.Upatre.Gen.3 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Upatre.Gen.3
TrendMicroTROJ_UPATRE.SMBX
Trapminemalicious.high.ml.score
SophosMal/Upatre-A
IkarusTrojan-Spy.Zbot
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojan/Bublik.gsj
VaristW32/Upatre.RA.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Waski
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Spy.Zbot.XGXB@56ryk0
ArcabitTrojan.Upatre.Gen.3
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan.Win32.Bublik.burd
MicrosoftTrojanDownloader:Win32/Upatre
GoogleDetected
AhnLab-V3Trojan/Win.Bublik.C5283973
Acronissuspicious
McAfeePWSZbot-FPU!8F96E0885143
MAXmalware (ai score=85)
VBA32BScope.Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMBX
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!9qysnvOtpJM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.36802.cuY@aqJSMjji
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.85143d
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Upatre.C(dyn)

How to remove Win32/Kryptik.BTEZ?

Win32/Kryptik.BTEZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment