Malware

Should I remove “Win32/Kryptik.EVKO”?

Malware Removal

The Win32/Kryptik.EVKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EVKO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.EVKO?


File Info:

name: EE179A2495B0EF02755B.mlw
path: /opt/CAPEv2/storage/binaries/d474e2ec3b3f8f53bb4fea4ac425e389ec3b85dc19279fdd49286467be18d758
crc32: BEC194BA
md5: ee179a2495b0ef02755bc0fba592b88f
sha1: 0a38e7748e2cb3b9509a3b0d02467c8713cdc9b3
sha256: d474e2ec3b3f8f53bb4fea4ac425e389ec3b85dc19279fdd49286467be18d758
sha512: 92f1d4f8f4f7abd19e278c294805d22868a01d612f819ce0dc88b71651ef56699e117fd6dd05beb1dd5d07ae99b93cbb1002c242526c63810397649e3727e757
ssdeep: 24576:55nzCF9ZjER+wJ1RkohtlhmLcgzIQEQFRxMHfp0SHExr:5Fz8etlUzIgM/p0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2F52847F7A3053DDACC8EB404CE077857544FD9D3E413AA1AAD3A943A3697C2C998AC
sha3_384: cc65d7c170edcf599966bde0946c110b9aa9d7e358a91c995082ab60d4af64d40dc42092c7cb54862695a3cb03c74996
ep_bytes: 558bec6aff68602775006838cf740064
timestamp: 2016-04-23 15:55:45

Version Info:

0: [No Data]

Win32/Kryptik.EVKO also known as:

tehtrisGeneric.Malware
MicroWorld-eScanApplication.Bundler.ICLoader.Gen.1
FireEyeGeneric.mg.ee179a2495b0ef02
CAT-QuickHealPUA.Softstor.Gen
McAfeePUP-FDV
VIPREApplication.Bundler.ICLoader.Gen.1
SangforPUA.Win32.Sign.a
K7AntiVirusTrojan ( 0055dd191 )
AlibabaAdWare:Win32/ICLoader.061c19aa
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.495b0e
BaiduWin32.Trojan.Kryptik.abx
VirITTrojan.Win32.Crypt5.BALR
CyrenW32/S-34fca371!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.EVKO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.ICLoader.gen
BitDefenderApplication.Bundler.ICLoader.Gen.1
NANO-AntivirusTrojan.Win32.InstallCube.ebtscc
AvastWin32:InstallCube-IO [Adw]
TencentMalware.Win32.Gencirc.10b3c699
Ad-AwareApplication.Bundler.ICLoader.Gen.1
EmsisoftApplication.Bundler.ICLoader.Gen.1 (B)
ComodoTrojWare.Win32.Crypt.B@7o6bny
DrWebTrojan.InstallCube.987
ZillyaAdware.ICLoaderCRTD.Win32.7827
TrendMicroTROJ_GEN.R002C0OHE22
McAfee-GW-EditionPUP-FDV
SophosICLoader (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.ICLoader.agu
AviraPUA/ICLoader.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.3F8B
MicrosoftPUADlManager:Win32/InstallCube
GDataWin32.Adware.InstallCore.HD
GoogleDetected
AhnLab-V3PUP/Win32.ICLoader.R180122
ALYacApplication.Bundler.ICLoader.Gen.1
MAXmalware (ai score=75)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesAdware.ICLoader
TrendMicro-HouseCallTROJ_GEN.R002C0OHE22
RisingTrojan.Generic@AI.100 (RDML:Ak12JaEZw7cBTsFoojD0Iw)
YandexTrojan.GenAsa!GLKi0RUnLME
IkarusTrojan-Spy.Win32.Zbot
MaxSecureAdware.W32.ICLoader.gen_234297
FortinetAdware/InstallCube
AVGWin32:InstallCube-IO [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Win32/Kryptik.EVKO?

Win32/Kryptik.EVKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment