Malware

How to remove “Win32/Kryptik.CLFE”?

Malware Removal

The Win32/Kryptik.CLFE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CLFE virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Win32/Kryptik.CLFE?


File Info:

name: 2246AA9FF64228E8D898.mlw
path: /opt/CAPEv2/storage/binaries/a6647c7f19c04fcfcc7a35d3a2db4289632ccb18ec26eb4bdb66593683fdc930
crc32: 615043C3
md5: 2246aa9ff64228e8d89821c6c5861f07
sha1: 95120a52e2e4112d842674b4d1840153fff90108
sha256: a6647c7f19c04fcfcc7a35d3a2db4289632ccb18ec26eb4bdb66593683fdc930
sha512: 6d1f756b530a72952867cbe7262d5d201bb348940885c47893330eef0c0703b452d336f11eaf1f9609892bf7517ba530cf4e381dbdf999c925251891f24a913c
ssdeep: 192:CTgEUjpDM5lVT7XJy1oynlEwww6mbQpar8ws/zZ:CxNZDJy1fS9mbQ68ws7Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171A26323E36D44E8F3AB863E512B415C881FEF707341A9DBF69C7061227638AD5B11E9
sha3_384: db62385152ca175cb94d900f36c6ecb743cce33005debce5b4e94efdb2a7ca06ab99c02393e489ff8b5c01e161a2365c
ep_bytes: 57565351e86af4ffffc3cccccccccccc
timestamp: 1973-03-03 10:26:47

Version Info:

CompanyName: JineJong
FileDescription: JineJong company
FileVersion: Version 2.5.23
InternalName: JineJong
LegalCopyright: Copyright by JineJong
OriginalFilename: JineJong
Translation: 0x040b 0x04e2

Win32/Kryptik.CLFE also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanDwnldr.Upatre.AA4
McAfeeDownloader-FSH
CylanceUnsafe
VIPRETrojan.Upatre.Gen.3
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderTrojan.Upatre.Gen.3
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.ff6422
BitDefenderThetaGen:NN.ZexaF.34582.bq1@a0OE@3jG
CyrenW32/Upatre.D.gen!Eldorado
SymantecDownloader.Upatre!gen5
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CLFE
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTSPY_ZBOT.SMRWS
ClamAVWin.Trojan.Upatre-3443
NANO-AntivirusTrojan.Win32.Upatre.dghaio
MicroWorld-eScanTrojan.Upatre.Gen.3
RisingDownloader.Upatre!1.A19D (CLASSIC)
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Troj/HkMain-AZ
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
ZillyaDownloader.Upatre.Win32.47
TrendMicroTSPY_ZBOT.SMRWS
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2246aa9ff64228e8
EmsisoftTrojan.Upatre.Gen.3 (B)
APEXMalicious
GDataWin32.Trojan.PSE1.QHQVJ
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.3CF7
ArcabitTrojan.Upatre.Gen.3
SUPERAntiSpywareTrojan.Agent/Gen-Renos
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
AhnLab-V3Trojan/Win32.Upatre.R120255
VBA32TrojanDownloader.Upatre
ALYacTrojan.Upatre.Gen.3
MAXmalware (ai score=86)
MalwarebytesMalware.AI.350260953
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.114968f8
YandexTrojan.Kryptik!6DG0oouZO9Q
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
AvastWin32:Agent-AULS [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.CLFE?

Win32/Kryptik.CLFE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment