Malware

Win32/Kryptik.CBUK removal instruction

Malware Removal

The Win32/Kryptik.CBUK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CBUK virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Kryptik.CBUK?


File Info:

name: 341027FF602A1A7971FE.mlw
path: /opt/CAPEv2/storage/binaries/6ebd19d2898ea26c017ccfd46a04b0cd0f0b8a1500233f52e45c0bc0f2b87f23
crc32: 74D67705
md5: 341027ff602a1a7971fed58c0643face
sha1: f6138b05b02bc78672c9747e306cbe51d0309109
sha256: 6ebd19d2898ea26c017ccfd46a04b0cd0f0b8a1500233f52e45c0bc0f2b87f23
sha512: 05f433da17b9d4971f725de84a7854273ffd6c22d61170de60a8cbddaf7a00228d61f4bcc3d2fb1dc083e703923344e7cce742fa23c695b4849669383cff284b
ssdeep: 1536:DwCd+qitb0bt+FTCQ2F9EvHsdX+u1x20n2eN6BRE:Dv4b0hX9EE1+u1x2q2eYRE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AE36A1275C0C432C81741751967CB4F7B27BB211AAA83BF378A538A9E717D1AD3E34A
sha3_384: b2002686f867fe9b396f3856a6bad5eb42a20bdd81410ceaf398174ade9165af36d2c79d6524955805d9669b6de1895e
ep_bytes: e85f140000e917feffffe8a3040000ff
timestamp: 2014-05-14 06:15:51

Version Info:

0: [No Data]

Win32/Kryptik.CBUK also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQRK
FireEyeGeneric.mg.341027ff602a1a79
ALYacTrojan.Downloader.JQRK
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3661930
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.f602a1
ArcabitTrojan.Downloader.JQRK
CyrenW32/Kryptik.FZX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.CBUK
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Downloader.JQRK
NANO-AntivirusTrojan.Win32.DownLoad3.cyhcfz
AvastWin32:Crypt-RSI [Trj]
TencentTrojan-spy.Win32.Zbot.thiya
Ad-AwareTrojan.Downloader.JQRK
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDownloader.Waski.OFE@5j48vd
DrWebTrojan.DownLoad3.33375
VIPRETrojan.Win32.Upatre.acc (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
EmsisoftTrojan.Downloader.JQRK (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan-Spy.Win32.Zbot.v
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.A1CBD0
MicrosoftTrojanDownloader:Win32/Upatre
GDataTrojan.Downloader.JQRK
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R106825
Acronissuspicious
McAfeePWSZbot-FRU!341027FF602A
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingMalware.FakePDF/ICON!1.A24E (RDMK:cmRtazpwU0V6hwO/nMipVGxUkJ8X)
YandexTrojan.Kryptik!SnonW740cho
IkarusTrojan-Downloader.Win32.Dofoil
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.D!tr
BitDefenderThetaGen:NN.ZexaF.34114.jmX@ai@G2Yni
AVGWin32:Crypt-RSI [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Kryptik.CBUK?

Win32/Kryptik.CBUK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment