Malware

Win32/Kryptik.IBO removal tips

Malware Removal

The Win32/Kryptik.IBO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.IBO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.IBO?


File Info:

name: A7B499B9A3B84561B55C.mlw
path: /opt/CAPEv2/storage/binaries/ae06f272362add72ec201879da7c2ddf79caa87c2ef2026cbbbc87ee4fd15d21
crc32: E61F67CE
md5: a7b499b9a3b84561b55c5bad6ff337fa
sha1: 2f8589b2edf9d2ba0b87a5e61d1f998499325e9d
sha256: ae06f272362add72ec201879da7c2ddf79caa87c2ef2026cbbbc87ee4fd15d21
sha512: 96a1ff3529febcb4213a7e1ae95c7ccbf07a164f7f32f5bb864846caa38dbf61bae838b90b0014afcc34bbea0fe4cbf85c8afc9ca192fa6767e64c9ee82537ae
ssdeep: 1536:I5FusSx9qYMhdFHS8qdydo3nTzhYxJA+CwNUtBZVY9v8prbzBvwX1pwMExaG4H:IvS4jHS8q/3nTzePCwNUh4E9bzyXTfE+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195930227ABF8FAC4DC4943706A235961DE09ED007C62CEDE0978793B5FB91631A43923
sha3_384: e3348cba62cd924e87dd9ea79e4035a504f0c729fee16b6e612b31af3038f3ac5f7e9b07b12c0cceac041ce31f48c872
ep_bytes: e8000000008304241c64ff3500000000
timestamp: 2010-07-14 22:04:13

Version Info:

FileDescription: zlib data compression library
FileVersion: 1.2.3
InternalName: zlib1.dll
LegalCopyright: (C) 1995-2004 Jean-loup Gailly & Mark Adler
OriginalFilename: zlib1.dll
ProductName: zlib
ProductVersion: 1.2.3
Comments: DLL support by Alessandro Iacopetti & Gilles Vollant
Translation: 0x0409 0x04b0

Win32/Kryptik.IBO also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader1.26310
MicroWorld-eScanGen:Variant.Razy.821660
FireEyeGeneric.mg.a7b499b9a3b84561
CAT-QuickHealBackdoor.Zegost.C3
SkyhighDropper-FAX!A7B499B9A3B8
ALYacGen:Variant.Razy.821660
Cylanceunsafe
ZillyaTrojan.GenericCRTD.Win32.197
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Razy.821660
K7GWTrojan ( 00379e621 )
K7AntiVirusTrojan ( 005257651 )
ArcabitTrojan.Razy.DC899C
BitDefenderThetaGen:NN.ZexaF.36804.fm1@aSbzbmgj
VirITTrojan.Win32.Generic.ABKF
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Kryptik.IBO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Zegost-9772629-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Kryptik.e11efe88
NANO-AntivirusTrojan.Win32.Bjlog.rdwiy
AvastWin32:Zegost-I [Drp]
TencentTrojan.Win32.Agent.q
EmsisoftGen:Variant.Razy.821660 (B)
F-SecureTrojan.TR/Tiarev.A
BaiduWin32.Trojan.Kryptik.t
TrendMicroTROJ_KRYPTK.SMUI
Trapminemalicious.high.ml.score
SophosMal/PWS-FY
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.mcgx
VaristW32/Downloader.AT.gen!Eldorado
AviraTR/Tiarev.A
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Kryptik.ibo
KingsoftWin32.Trojan.Generic.a
XcitiumBackdoor.Win32.Popwin.~IQ@ogvrk
MicrosoftBackdoor:Win32/Zegost
ViRobotBackdoor.Win32.A.Zegost.97480.T
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.821660
GoogleDetected
AhnLab-V3Trojan/Win32.Bjlog.R23262
McAfeeDropper-FAX!A7B499B9A3B8
TACHYONBackdoor/W32.Zegost.97480.C
VBA32SScope.Adware.Baidu.01015
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMUI
RisingTrojan.Kryptik!1.ADBE (CLASSIC)
YandexPacked/NSPack
IkarusTrojan-Dropper.Win32.Swisyn
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Genome.AFT!tr
AVGWin32:Zegost-I [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Razy

How to remove Win32/Kryptik.IBO?

Win32/Kryptik.IBO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment