Malware

What is “Win32/Kryptik.EEOW”?

Malware Removal

The Win32/Kryptik.EEOW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EEOW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Win32/Kryptik.EEOW?


File Info:

crc32: D3AF6460
md5: a0f4494a6292ba5d671d82b715bb6413
name: A0F4494A6292BA5D671D82B715BB6413.mlw
sha1: 7b78b23b2b2693a0ce03f54e182bdd410794a2e8
sha256: 7c40de8e3dbfc216b15fed197b4bd83eb6f8280b1eab3c090f7d6beafd481351
sha512: 6d81e78efae83b7844e1b205f14e8e5469bfe7e51e00370bbceda0f1345d9af8b7dc8a9e45165424e91f07d8acda809af4f9f10a9c331eff3b802d9b83260e93
ssdeep: 6144:esKEeL2SOykWOvvbrG3oHPT8UNuklcSuGk6rPdSZSys/z:JLs2DrWS3bvBNuklDuGNrPd0s/z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: REVisionFX
FileVersion: 2.8.5.0
CompanyName: REVisionFX
ProductName: Pack 2015 UP4
ProductVersion: 2.8.5.0
FileDescription: Pack 2015 UP4
Translation: 0x0409 0x04b0

Win32/Kryptik.EEOW also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.BrsecmonE.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Foreign.6f60e527
K7GWTrojan ( 004ce0eb1 )
K7AntiVirusTrojan ( 004ce0eb1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EEOW
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nqaq
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Kryptik.evecan
MicroWorld-eScanTrojan.BrsecmonE.1
TencentWin32.Trojan.Foreign.Lnea
Ad-AwareTrojan.BrsecmonE.1
ComodoMalware@#2prbzchly1fre
F-SecureHeuristic.HEUR/AGEN.1128658
BitDefenderThetaAI:Packer.7D01422521
VIPRELookslike.Win32.Crowti.an!ag (v)
TrendMicroRansom_HPLOCKY.SME
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.a0f4494a6292ba5d
EmsisoftTrojan.BrsecmonE.1 (B)
JiangminTrojan.Foreign.dig
AviraHEUR/AGEN.1128658
Antiy-AVLTrojan[Ransom]/Win32.Foreign
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.BrsecmonE.1
AegisLabTrojan.Win32.Foreign.j!c
ZoneAlarmTrojan-Ransom.Win32.Foreign.nqaq
GDataTrojan.BrsecmonE.1
Acronissuspicious
McAfeeArtemis!A0F4494A6292
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Farfli
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME
RisingTrojan.Generic@ML.100 (RDML:Gc6tQl+zk1rmoHEEhD2Wpw)
YandexTrojan.Foreign!YqALY/GM4ro
IkarusTrojan-Ransom.GandCrab
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.d27

How to remove Win32/Kryptik.EEOW?

Win32/Kryptik.EEOW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment