Malware

Win32/Kryptik.EEVG malicious file

Malware Removal

The Win32/Kryptik.EEVG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EEVG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Upatre downloader
  • Attempts to modify proxy settings
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
icanhazip.com

How to determine Win32/Kryptik.EEVG?


File Info:

crc32: DDE6DE1A
md5: 164be333c6d0d8c10c85eef63b10d91f
name: 164BE333C6D0D8C10C85EEF63B10D91F.mlw
sha1: e1210e10e9e473610a5cc116af33b1a69dfbbb31
sha256: f8f3a30630d7be83242535bd984e18aaf3a87de15bc6b3a866861373b445690f
sha512: 6b4c4926184a134a6f03a831c4fb13777effe208e3b117591b3c1828696d73f5dda8d7381db72e252937d2ce4c6c1adc054eac3c2c22b1b9d648ae6922aa3d90
ssdeep: 384:sxVbjozjGL59XsOX8qVEGQyQ/HaPQK9u8erXmcFAfBcpHUOK41024J+dYxpmBHo:4VI+LfrsFtGMXXmBqhF0DsgpmF3u/f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.EEVG also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.1
FireEyeGeneric.mg.164be333c6d0d8c1
McAfeeDownloader-FAHF!164BE333C6D0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderTrojan.Upatre.Gen.1
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.3c6d0d
BitDefenderThetaGen:NN.ZexaF.34804.bCX@amathxfi
CyrenW32/Upatre.GF.gen!Eldorado
SymantecDownloader.Upatre!g18
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.MlwGen.dysysh
RisingTrojan.Win32.Kryptik.an (CLOUD)
Ad-AwareTrojan.Upatre.Gen.1
SophosML/PE-A + Troj/Upatre-WK
ComodoTrojWare.Win32.TrojanDownloader.Upatre.PUD@65ocu5
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Kryptik.rl
TrendMicroTROJ_UPATRE.SMDJM
McAfee-GW-EditionBehavesLike.Win32.Worm.mh
EmsisoftTrojan.Upatre.Gen.1 (B)
IkarusTrojan.Kryptik
JiangminTrojan.Generic.fkzp
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanDownloader:Win32/Upatre!rfn
ArcabitTrojan.Upatre.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Upatre.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R168295
Acronissuspicious
VBA32BScope.Trojan.Dynamer
ALYacTrojan.Upatre.Gen.1
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.EEVG
TrendMicro-HouseCallTROJ_UPATRE.SMDJM
TencentWin32.Trojan.Crypt.Dwtn
YandexTrojan.Kryptik!2k7HGkiBqRg
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EEVG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.Malware.Gen

How to remove Win32/Kryptik.EEVG?

Win32/Kryptik.EEVG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment