Malware

Win32/Kryptik.CSH information

Malware Removal

The Win32/Kryptik.CSH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CSH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.CSH?


File Info:

name: 5EC672D20968B3AC5EF8.mlw
path: /opt/CAPEv2/storage/binaries/002835278335fdcf1f693d18aea80d0315ff54e39ef310e49c7338946fee7dc7
crc32: DEE908F6
md5: 5ec672d20968b3ac5ef87d1d705306f8
sha1: b888b01113568ea127a86302b5ee6990a908908a
sha256: 002835278335fdcf1f693d18aea80d0315ff54e39ef310e49c7338946fee7dc7
sha512: c9698d8f1d26eae246b5b8606cbcf1116057e4291a24a440761567edc8a6dda6e1aef528eb2c0f751d163d15a197df72781f3931e88dc44a045ac8906a1a3293
ssdeep: 384:urx2/10mPNmdqm2wXg4l+fEt/HKE4eJ8HrQ8Qhc22kxj5+u:W2/O2NmMm2wXtl+gHKTLrLQh2kUu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5A2C0677E0F8669D181CAF1CA50161FE94743D470B2E62ACE67E2093C2B6B97A78530
sha3_384: af84eff1d45289758ab2fd379f7a369cfde2e2e38b9fe18b7fc5653f5e4e1fd642aed40404d16b15794324895cc7ee94
ep_bytes: 89e68b0681e8010000008038c375f5ff
timestamp: 2008-01-21 23:13:23

Version Info:

0: [No Data]

Win32/Kryptik.CSH also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.kZ31
MicroWorld-eScanGen:Trojan.Generic.bmW@a8A8uwg
ClamAVWin.Downloader.39885-1
McAfeeArtemis!5EC672D20968
CylanceUnsafe
ZillyaTrojan.FraudPack.Win32.23888
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderGen:Trojan.Generic.bmW@a8A8uwg
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.20968b
VirITTrojan.Win32.Adload.MC
CyrenW32/Downloader.NYNV-1952
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CSH
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Pincav.e5a764f3
NANO-AntivirusTrojan.Win32.Small.naod
ViRobotTrojan.Win32.Downloader.22016.AN
RisingMalware.Undefined!8.C (TFE:5:sw8hBQ7H39C)
Ad-AwareGen:Trojan.Generic.bmW@a8A8uwg
EmsisoftGen:Trojan.Generic.bmW@a8A8uwg (B)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
DrWebWin32.HLLW.Autoruner.35253
VIPREGen:Trojan.Generic.bmW@a8A8uwg
TrendMicroTROJ_SMALL.BXJ
McAfee-GW-EditionBehavesLike.Win32.Dropper.mh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5ec672d20968b3ac
SophosML/PE-A + Mal/Spyzee-A
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanDownloader.Small.zze
WebrootW32.Malware.Downloader
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.8
KingsoftWin32.Troj.FraudPack.g.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Trojan.Generic.bmW@a8A8uwg
GoogleDetected
AhnLab-V3Win-Trojan/Fraudpack.Gen
BitDefenderThetaAI:Packer.CE3E07A51B
ALYacGen:Trojan.Generic.bmW@a8A8uwg
MAXmalware (ai score=100)
VBA32Malware-Cryptor.General.2
MalwarebytesMachineLearning/Anomalous.100%
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SMALL.BXJ
TencentWin32.Trojan.Dropper.Kzfl
YandexTrojan.GenAsa!ztEffwfBEb4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FraudPack.B!tr
AVGWin32:Ups [Cryp]
AvastWin32:Ups [Cryp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.CSH?

Win32/Kryptik.CSH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment