Malware

Win32/Kryptik.IML malicious file

Malware Removal

The Win32/Kryptik.IML is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.IML virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.IML?


File Info:

name: FAE8E54F18047DF362F2.mlw
path: /opt/CAPEv2/storage/binaries/32452ba1d099eee516cb0f88a9f02c2401f27785ff9b46d52ddb5cc2effccd30
crc32: 46300A61
md5: fae8e54f18047df362f29304bcfa1566
sha1: 0b6afcac9d994ad9861bc0d45722df31aa3c8983
sha256: 32452ba1d099eee516cb0f88a9f02c2401f27785ff9b46d52ddb5cc2effccd30
sha512: 9ad208f2a1386632a44906909fab3923a6b555bc871d4cc71bb716390943c35001c1744af70f82fb79615538fcbee2239854649016d6e48096dab306d58a5950
ssdeep: 1536:Qpnxm6MG9xgfrvEaoiT/GyphjXDYjKwttoswRmhApEL:GnxwgxgfR/DVG7wBpEL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15893C069BF833F9BD0BD8C3759F3746C086835897E407C2A6AB4014B57B590E8F25A78
sha3_384: d3c3b80916e1d56db2259869109f602c5b81f448e62248950dc88dc767ad9836b2a832477b287e31bd0ab3cf4e23baa1
ep_bytes: 558bec83ec2c8165f4000000002b3d99
timestamp: 2002-03-28 06:53:52

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Shockwave Flash 6.0 r65
FileExtents: swf|spl
FileOpenName: Macromedia Flash movie (*.swf)|FutureSplash movie (*.spl)
MIMEType: application/x-shockwave-flash|application/futuresplash
ProductName: Shockwave Flash
FileVersion: 6,0,65,0
InternalName: Macromedia Flash Player 6.0
LegalCopyright: Copyright © 1996-2002 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: npswf32.dll
ProductVersion: 6,0,65,0
Translation: 0x0409 0x04b0

Win32/Kryptik.IML also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.ltgH
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.KS.2
FireEyeGeneric.mg.fae8e54f18047df3
CAT-QuickHealW32.Ramnit.DR
McAfeeW32/Ramnit.y
CylanceUnsafe
ZillyaTrojan.Krap.Win32.4
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001f82c71 )
K7GWTrojan ( 0041ada71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.A20BC7AF14
VirITTrojan.Win32.Shiru.Z
CyrenW32/SuspPack.DC.gen!Eldorado
SymantecPacked.Protexor!gen1
ESET-NOD32a variant of Win32/Kryptik.IML
TrendMicro-HouseCallTROJ_DROPPR.SMAL
ClamAVWin.Malware.Ramnit-6736539-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.KS.2
NANO-AntivirusTrojan.Win32.Lebag.csapu
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptic
AvastWin32:GenMalicious-HQA [Trj]
RisingTrojan.Win32.ZBot.bx (CLASSIC)
Ad-AwareGen:Trojan.Heur.KS.2
EmsisoftGen:Trojan.Heur.KS.2 (B)
ComodoTrojWare.Win32.Kryptik.IQC@3nvynu
DrWebTrojan.Inject.14349
VIPREGen:Trojan.Heur.KS.2
TrendMicroTROJ_DROPPR.SMAL
McAfee-GW-EditionW32/Ramnit.y
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Ramnit-ZZ
APEXMalicious
GDataGen:Trojan.Heur.KS.2
JiangminTrojan/Lebag.wb
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Heur.KVM011.a.(kcloud)
MicrosoftTrojan:Win32/Orsam!rts
GoogleDetected
AhnLab-V3Trojan/Win32.Ramnit.R7595
VBA32BScope.Trojan.Inject
TACHYONTrojan/W32.Krap.95149
MalwarebytesGeneric.Trojan.Malicious.DDS
IkarusTrojan.Win32.Lebag
TencentTrojan.Win32.Koobface.a
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.LW!tr
AVGWin32:GenMalicious-HQA [Trj]
Cybereasonmalicious.f18047
PandaW32/Koobface.LO.worm

How to remove Win32/Kryptik.IML?

Win32/Kryptik.IML removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment