Malware

How to remove “Win32/Kryptik.EZPY”?

Malware Removal

The Win32/Kryptik.EZPY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EZPY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

How to determine Win32/Kryptik.EZPY?


File Info:

crc32: FE60AA9E
md5: b2412d559f64cc86b833f030674c4dd2
name: B2412D559F64CC86B833F030674C4DD2.mlw
sha1: 17b9877231980d4bdccfd34dd20312d81887a229
sha256: 3018262f069e2a07d7411dd71381fc3170e3da6067193d7c9836af375187ea38
sha512: d362fdb3aaf5f8ddf0f503f5eea52d92999d27b9e28d4a6087c5a7593bec3e9e133dcd1b2fc307302d1f4c86f810d85d3f216c34fc41ff279145be0f05ebd934
ssdeep: 3072:F3fvX6hINiX2w1pxWv+sOkLzByf1QxGCYIWiUse/VgnG:VgEi1pxWvukzByasIWz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2008-2011 x41ex41ex41e x42fx43dx434x435x43ax441
InternalName: Punto Switcher Unloader
FileVersion: 3.2.3.51
CompanyName: x41ex41ex41e x42fx43dx434x435x43ax441
LegalTrademarks: Punto Switcher
Comments: x412x44bx433x440x443x437x447x438x43a Punto Switcher
ProductName: Punto Switcher
ProductVersion: 3.2.3.51
FileDescription: x412x44bx433x440x443x437x447x438x43a Punto Switcher
OriginalFilename: puntounloader.exe
Translation: 0x0419 0x04b0

Win32/Kryptik.EZPY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.G4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1306335
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.59f64c
BaiduWin32.Trojan.Kryptik.awh
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.EZPY
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Ransomware.Cerber-6931819-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Kryptik.evqhck
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Pcrx
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Cerber-AK
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
BitDefenderThetaGen:NN.ZexaF.34686.qq0@au89K4ek
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroRansom_CERBER.SMEJ5
McAfee-GW-EditionBehavesLike.Win32.DialerSuspicious.dh
FireEyeGeneric.mg.b2412d559f64cc86
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129194
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
McAfeeRansomware-GCQ!B2412D559F64
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Cerber
MalwarebytesMalware.AI.3495264953
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.SMEJ5
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoPU538WmPJze8501+k+h/7)
IkarusTrojan.Win32.Filecoder
FortinetW32/Qbot.CQ!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Win32/Kryptik.EZPY?

Win32/Kryptik.EZPY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment