Malware

How to remove “Win32/Kryptik.CTPM”?

Malware Removal

The Win32/Kryptik.CTPM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CTPM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.CTPM?


File Info:

name: 047F720C4C2047656F84.mlw
path: /opt/CAPEv2/storage/binaries/f501e43831071101d8660e7aec279cfbc74d4e93fbd067d0f92b737e3b750dc2
crc32: 4191CBF4
md5: 047f720c4c2047656f842bb5ede45f86
sha1: 0b6b18143c3897c139bee4e0f6b855a2041b75af
sha256: f501e43831071101d8660e7aec279cfbc74d4e93fbd067d0f92b737e3b750dc2
sha512: 00ba5e26052a9c4b0a9da67fb29b26a4391171319e6582b3ef93d9dc08bdd2da6fd9ffe1b0d142789f35a5dc7d6cc22457b8fa573ea919b04b147cd983b20024
ssdeep: 12288:TLc/KNGOzG3Kfo++9Q08/yz2NyJ/2dBig32soRwpoMqUiSndxa:pt7j0tH52OktE84Sndxa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174B40283D743CBF2C2B939F9568F5E040A2425D401502F4793EEEDAAB2D6BB1751B6C8
sha3_384: a5fc3eb8c04c96e7907c7c9a9c30418be14e84638a5432be748f6adaabfb0dce044678e158f2f41cfc49575b748ca03f
ep_bytes: 558bec81ecec000000b95aa70000898d
timestamp: 2012-03-24 11:06:32

Version Info:

ProductVersion: 11.31.2119.57992
OriginalFilename: baess.exe
CompanyName: Emnsiem Corporatu
FileDescription: Emnsiem Visatl Studie 2020
InternalName: baess.exe
FileVersion: 11.31.2119.57992
Translation: 0x0409 0x04b0

Win32/Kryptik.CTPM also known as:

LionicTrojan.Win32.Zbot.mf8l
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.7719
MicroWorld-eScanGen:Heur.Variadic.A.110.1
FireEyeGeneric.mg.047f720c4c204765
ALYacGen:Heur.Variadic.A.110.1
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.171643
SangforTrojan.Win32.Kryptik.CTPM
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.c4c204
BitDefenderThetaGen:NN.ZexaF.34646.Fq1@aCf8tjEG
VirITTrojan.Win32.Banker.ALG
CyrenW32/Zbot.VQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CTPM
APEXMalicious
TrendMicro-HouseCallTSPY_ZBOT.SMAC
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-61998
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Variadic.A.110.1
NANO-AntivirusTrojan.Win32.MlwGen.dkqdsz
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:Agent-AUYE [Trj]
TencentTrojan.Win32.Zbot.c
Ad-AwareGen:Heur.Variadic.A.110.1
TACHYONTrojan-Spy/W32.ZBot.508486
EmsisoftGen:Heur.Variadic.A.110.1 (B)
ComodoTrojWare.Win32.Spy.Zbot.UDSF@5imov1
BaiduWin32.Trojan.Kryptik.je
VIPREGen:Heur.Variadic.A.110.1
TrendMicroTSPY_ZBOT.SMAC
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-JJI
IkarusTrojan-Spy.Zbot
JiangminTrojanSpy.Zbot.ehea
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPWS:Win32/Zbot
GDataGen:Heur.Variadic.A.110.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R129010
McAfeeTrojan-FFFI!047F720C4C20
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Panda
MalwarebytesTrojan.Zemot
RisingTrojan.Crypto!8.364 (TFE:2:p9LxMZDhweV)
YandexTrojan.GenAsa!gWwDhtM/1ms
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.CSQU!tr
AVGWin32:Agent-AUYE [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.CTPM?

Win32/Kryptik.CTPM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment