Malware

Win32/Kryptik.EDR removal instruction

Malware Removal

The Win32/Kryptik.EDR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EDR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.EDR?


File Info:

name: 194EDD82661ED225D824.mlw
path: /opt/CAPEv2/storage/binaries/07dcb453fb31466ccbcf73fd401a68b3d9cfa9637fcd9959cdb9608deb050888
crc32: 02EFED32
md5: 194edd82661ed225d82459de74d1738b
sha1: 3fb4759caaa3fb1f8c3573bdf80b53b15e9c2b28
sha256: 07dcb453fb31466ccbcf73fd401a68b3d9cfa9637fcd9959cdb9608deb050888
sha512: aa5ab829f22119cb148c4801245a01209a52b2dd887460f15d74aad52a39cb798659c09606397bff9ff2d20d39e3402919d03c45855ac9ef96d22e3380f97d63
ssdeep: 49152:4Cc005BGzw5ubtxOz1RAVPo7J6vbcG8byCk7V:4Xyw5Q8mQbyCQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A95337273BE3DFEC483087192B49B61935010F99B0E2D87DF4A685428A72B770B679D
sha3_384: 2aa5a38c9a6fdff3945f36deddc15337a9efdd748b0e503e3b3ec20f3fa538e3d89cb56e39c626fdbea34d7554887402
ep_bytes: 558bec81ecd0020000c685d3fdffff22
timestamp: 2009-06-18 07:16:55

Version Info:

CompanyName: TWX Corp.
FileDescription: Windows NT ClipBook Viewer
FileVersion: 4.2.2700.5512
InternalName: PR2S
LegalCopyright: TWX Corporation. All rights reserved
OriginalFilename: PR2S.EXE
ProductName: PR2S
ProductVersion: 4.2.2700.5512
Translation: 0x0409 0x04b0

Win32/Kryptik.EDR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Krypt.22
FireEyeGeneric.mg.194edd82661ed225
ALYacGen:Heur.Krypt.22
CylanceUnsafe
VIPREGen:Heur.Krypt.22
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005325641 )
K7GWTrojan ( 005325641 )
Cybereasonmalicious.2661ed
VirITTrojan.Win32.Papras.VE
CyrenW32/Risk.BLOP-8841
ESET-NOD32a variant of Win32/Kryptik.EDR
APEXMalicious
ClamAVWin.Trojan.Agent-253107
KasperskyPacked.Win32.Krap.ao
BitDefenderGen:Heur.Krypt.22
NANO-AntivirusTrojan.Win32.Papras.tagj
AvastWin32:Crypt-FWN [Trj]
Ad-AwareGen:Heur.Krypt.22
EmsisoftGen:Heur.Krypt.22 (B)
ComodoTrojWare.Win32.PkdKrap.AO@2mkvi8
DrWebTrojan.PWS.Panda.114
ZillyaTrojan.Papras.Win32.349
TrendMicroMal_Bredlab2
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-BW
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Krypt.22
JiangminPacked.Krap.bmdb
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4
ViRobotTrojan.Win32.PSWPapras.421888
ZoneAlarmPacked.Win32.Krap.ao
MicrosoftPWS:Win32/Zbot.PG
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Burnix.R2734
McAfeePWS-Zbot.gen.ak
MAXmalware (ai score=85)
VBA32BScope.TrojanDownloader.Unruy
TrendMicro-HouseCallMal_Bredlab2
RisingDownloader.Harnig!8.28D (TFE:2:yRF76S8n8jD)
YandexTrojan.PWS.Zbot!42ZBWJ9SSdg
IkarusTrojan.Win32.Ransom
FortinetW32/Krapt.AOA!tr
BitDefenderThetaAI:Packer.B0FB4B6D1F
AVGWin32:Crypt-FWN [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Kryptik.EDR?

Win32/Kryptik.EDR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment