Malware

Should I remove “Win32/Kryptik.DUIB”?

Malware Removal

The Win32/Kryptik.DUIB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DUIB virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Zulu
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io
teenpornotube.org
www.teenpornotube.org
ledshoppen.nl
ezglobalmarketing.com
www.hugedomains.com
ocsp.digicert.com
shmetterheath.ru
fgainterests.com

How to determine Win32/Kryptik.DUIB?


File Info:

crc32: 93021C56
md5: 1983db73d3e4e1c548a321db868ed958
name: 1983DB73D3E4E1C548A321DB868ED958.mlw
sha1: 5df8c1cf76cc86917c574c7ffc0e461b60e0a94c
sha256: 76aacb5760ac8830244d8404cc4c9d9fc3f9a22480e1998a67c22f8df9d722d1
sha512: 06abf18ea96eba95171240fe8eef777480ecd21ad561027ed2dfe1f5ef0bdf1f98bb84910eae23c77f46662501de3e4c002137226dbcbdb4292560a7242245a3
ssdeep: 6144:2hx2eym+4DemeXf7g0bmH/ER0MuWR305xkevLLGD5Y5teJ:2hx2ehc1f7WHW0MdRkJLv2J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Pint xa9 1936
InternalName: Paddled
FileVersion: 133, 15, 169, 112
CompanyName: Relic Entertainment
ProductName: Oppression Innovation
FileDescription: Mockup
OriginalFilename: Jellify.exe

Win32/Kryptik.DUIB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.54518
CynetMalicious (score: 100)
CAT-QuickHealRansom.TeslaCrypt.WR4
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.578
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.3d3e4e
ESET-NOD32a variant of Win32/Kryptik.DUIB
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Deshacop.dvvuth
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
TencentMalware.Win32.Gencirc.114c7ac8
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-R + Mal/Tinba-L
ComodoMalware@#3jvza9zezwy41
BitDefenderThetaGen:NN.ZexaF.34692.tq3@amiDjCmG
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionTeslaCrypt!1983DB73D3E4
FireEyeGeneric.mg.1983db73d3e4e1c5
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.kx
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1117937
Antiy-AVLTrojan/Generic.ASMalwS.17A707F
ArcabitTrojan.Cripack.Gen.1
ZoneAlarmTrojan.Win32.Deshacop.vw
MicrosoftRansom:Win32/Tescrypt.A
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeTeslaCrypt!1983DB73D3E4
TACHYONTrojan/W32.Deshacop.326386
VBA32BScope.Trojan.Deshacop
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!kLIYn86dsjY
IkarusTrojan.Win32.Deshacop
eGambitGeneric.Malware
FortinetW32/Deshacop.XO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.DUIB?

Win32/Kryptik.DUIB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment