Malware

How to remove “Win32/Kryptik.KTC”?

Malware Removal

The Win32/Kryptik.KTC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.KTC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.KTC?


File Info:

name: 5294B6B2F9D3F98A5D18.mlw
path: /opt/CAPEv2/storage/binaries/01690fe4809a21af49598d32ffe7e12962903b1f5870c77ec08007c226ed6534
crc32: EEC2A798
md5: 5294b6b2f9d3f98a5d18bb78eb7c4d15
sha1: 69ddf8c834a984fc03f21cb1ef13537ea83e87c3
sha256: 01690fe4809a21af49598d32ffe7e12962903b1f5870c77ec08007c226ed6534
sha512: 6c92019021c8e6058337b7029b75a1673b6d62fcb5adf908db16a4b97c9c467818dbecb9e024268189fab3bf55ee0ac2abec093a18d083ca9c71676c0d541794
ssdeep: 3072:Qhhok4R5OpQ1Q7kac9Ujz8SVwaTNXQaRDwn5:QMVV1fmn8SRNX/RDwn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8C30119A2F00C25D1B0EBBCEB6FDA718E31D5F9AE1346034313D669ED708DF9A14A25
sha3_384: 414e005c57d81be2e4d4633da831464efa5886ef0506a1bd31e2927a1f565628bcfb46eac988c41fd168e5be7fbfb799
ep_bytes: e861220000909090909052e86e220000
timestamp: 2009-08-07 20:28:47

Version Info:

Comments:
CompanyName: ComponentOne LLC
FileDescription: kDrWeb For Windows 2011
FileVersion: 5.0.572.1152
InternalName: Dr.Web for Windows q6
LegalCopyright: Copyright (C) 40 DoctorWeb, Ltd., 1992-2011
LegalTrademarks:
OriginalFilename: 1nFile Protectoru v2011 Mn.exe
ProductName: Dr.Web for Windows 0
ProductVersion: 5.0.572.1152
Translation: 0x0419 0x04e3

Win32/Kryptik.KTC also known as:

BkavW32.RenosQKBU.Fam.Trojan
LionicTrojan.Win32.CodecPack.4!c
AVGWin32:Downloader-FTC [Trj]
MicroWorld-eScanGen:Heur.Conjar.9
FireEyeGeneric.mg.5294b6b2f9d3f98a
CAT-QuickHealTrojan.Renos.LX
SkyhighBehavesLike.Win32.Expiro.cc
McAfeeDownloader-CEW.x
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.47885
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/FlashApp.810a8a8f
K7GWTrojan ( 005485311 )
K7AntiVirusTrojan ( 005485311 )
BitDefenderThetaGen:NN.ZexaF.36804.hq0@aW!aJJpi
VirITTrojan.Win32.Letter.U
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.KTC
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Downloader-FTC [Trj]
ClamAVWin.Trojan.FakeAV-14042
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.CodecPack.hcgqo
TencentMalware.Win32.Gencirc.10b6f8b7
EmsisoftGen:Heur.Conjar.9 (B)
F-SecureTrojan-Downloader:W32/Renos.GTX
DrWebTrojan.DownLoader3.239
VIPREGen:Heur.Conjar.9
TrendMicroTROJ_FAKEAV.SM1C
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IZ
Paloaltogeneric.ml
JiangminTrojanDownloader.CodecPack.bzw
WebrootW32.Fakealert.Gen
VaristW32/FakeAlert.KN.gen!Eldorado
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.CodecPack
KingsoftWin32.NotVirus.FlashApp.a
MicrosoftTrojanDownloader:Win32/Renos.PT
XcitiumTrojWare.Win32.Kryptik.VL@2qgufe
ArcabitTrojan.Conjar.9
ViRobotTrojan.Win32.A.Downloader.128512.B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Conjar.9
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R2894
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
TACHYONTrojan-Downloader/W32.CodecPack.128512.C
MalwarebytesTrojan.Agent
PandaAdware/Antivir2010
TrendMicro-HouseCallTROJ_FAKEAV.SM1C
RisingDownloader.Renos!8.1D0 (TFE:2:wjUts5Z1o0J)
YandexTrojan.DL.CodecPack!Jmkuqh5Y/Xk
IkarusTrojan-Downloader.Win32.CodecPack
FortinetW32/Krypt.QKV!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Conjar

How to remove Win32/Kryptik.KTC?

Win32/Kryptik.KTC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment