Malware

Should I remove “Win32/Kryptik.DRSF”?

Malware Removal

The Win32/Kryptik.DRSF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DRSF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Win32/Kryptik.DRSF?


File Info:

name: B5E2F80830BF0DA374A7.mlw
path: /opt/CAPEv2/storage/binaries/f190b8012d0b33897ebacc7f4fa6cb464f2106987f573cf7adc8329b73130b1f
crc32: 67BCF280
md5: b5e2f80830bf0da374a77e9d1d717da5
sha1: 91f204742e847d63a94eb77003b5b3685787821a
sha256: f190b8012d0b33897ebacc7f4fa6cb464f2106987f573cf7adc8329b73130b1f
sha512: bb77194e7968d51b20750c320c529e184eb445ee07e5c8bfb2c4d75188100feb8319814536ad976bda03b5529b3558c8b30e3ee6220cad98315de5ee0866b75a
ssdeep: 1536:ooQMr1VPQcU4lTmPV/61xonpHmk+VFIV7k7kwy8N6xiJ:71r1BVlqPN61xodIFMA74xi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F63192262D48071E5611F3CD075A6D2066BBE217EF4F08F6E8835EC5F736C06AB9726
sha3_384: 50602e7dfb73b61f59b9aec92ba8ad6c58ba668b9fa7ed8415cb9f5c8043f1f505c2e35932d800c478997070c0a2d3c0
ep_bytes: e83d280000e9011e0000558bec518b45
timestamp: 2015-01-27 13:49:55

Version Info:

CompanyName: Aloseeye
FileDescription: Closeeye
FileVersion: 1.1.2.17
InternalName: AloseeyeInternal
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Aloseeye
ProductVersion: 2.1
Translation: 0x0415 0x04e5

Win32/Kryptik.DRSF also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Trojan.Ipatre.1
CAT-QuickHealTrojan.Kadena.B4
McAfeeUpatre-FACX!B5E2F80830BF
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.48106
K7AntiVirusTrojan ( 0056e8371 )
K7GWTrojan ( 0056e8371 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34114.eu1@aybWVYfG
CyrenW32/S-2ef997de!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DRSF
BaiduWin32.Trojan.Kryptik.lx
TrendMicro-HouseCallTROJ_UPATRE.SM37
KasperskyTrojan-Downloader.Win32.Upatre.eguw
BitDefenderGen:Trojan.Ipatre.1
NANO-AntivirusTrojan.Win32.Upatre.duzizn
AvastWin32:Malware-gen
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareGen:Trojan.Ipatre.1
SophosML/PE-A + Mal/Upatre-V
ComodoTrojWare.Win32.TrojanDownloader.Upatre.EMD@5syzmz
DrWebTrojan.DownLoader15.52932
VIPRETrojan-Downloader.Win32.Upatre.tfl (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionUpatre-FACX!B5E2F80830BF
FireEyeGeneric.mg.b5e2f80830bf0da3
EmsisoftGen:Trojan.Ipatre.1 (B)
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan.Kryptik.CI
JiangminTrojanDownloader.Upatre.tho
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.133825B
ArcabitTrojan.Ipatre.1
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R164221
Acronissuspicious
VBA32TrojanDownloader.Upatre
ALYacGen:Trojan.Ipatre.1
MalwarebytesTrojan.Dropper
RisingTrojan.Kryptik!1.A0CC (RDMK:cmRtazpj2smUWtl8WdLkPNLokz+3)
YandexTrojan.GenAsa!5bOQjy6rM5k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptic.ABGK!tr
AVGWin32:Malware-gen
Cybereasonmalicious.830bf0
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.DRSF?

Win32/Kryptik.DRSF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment