Malware

Win32/Kryptik.MOS removal instruction

Malware Removal

The Win32/Kryptik.MOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.MOS virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/Kryptik.MOS?


File Info:

name: 7AF9543325B8028B9015.mlw
path: /opt/CAPEv2/storage/binaries/fced3fecc23172a2d0e7e23e1340933a6ce576316308261640d88da0744f16cd
crc32: 594A2045
md5: 7af9543325b8028b90151c965d077a68
sha1: ef1c592932ce5036aa193c75e6d3d9e04778cb04
sha256: fced3fecc23172a2d0e7e23e1340933a6ce576316308261640d88da0744f16cd
sha512: 74645760965bc41f8ca66ddcf213ec5f19f7e8745b3f66b9cccc39e1cf613e97e626119c0c970dca5b196674167e77696940be7a2c07cb5960a56953cdfe8f10
ssdeep: 196608:oy8rtgRQortxUlX84nrfkCbwLiP9ZT2qB/8zqyc2:r8rtLmwG49wiZzB/Cqw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148663386034CE9EDF5510E7ED482CCF3A0DD6D43A595582238957DBEFABB880806F35A
sha3_384: ee3e9920b9c709411155c98072daabe3dfeb09ed3cfb3ffd9292e479ca6a5b22a0bd3001f6d59f2a91690bec276c25d1
ep_bytes: 60be0020d0008dbe00f06fffc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Win32/Kryptik.MOS also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.ArchSMS.lmoi
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
FireEyeGeneric.mg.7af9543325b8028b
CAT-QuickHealHoax.Archsms.21852
McAfeeArtemis!7AF9543325B8
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
AlibabaVirTool:Win32/Obfuscator.dd67ecb4
Cybereasonmalicious.325b80
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MOS
APEXMalicious
ClamAVWin.Adware.Agent-451618
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b878ec
Ad-AwareGen:Variant.Adware.SMSHoax.25
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
ComodoMalware@#1qx9x85opkw81
DrWebTrojan.SMSSend.473
ZillyaTrojan.ArchSMS.Win32.377
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/EncPk-ZC
Ikarusnot-a-virus:Hacktool.SMSHoax
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.loa
AviraJOKE/ArchSMS.JE
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.323628A
ArcabitTrojan.Adware.SMSHoax.25
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Obfuscator.QR
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.2C64342220
ALYacGen:Variant.Adware.SMSHoax.25
VBA32Trojan.Zeus.EA.0999
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Kryptik.MOS?

Win32/Kryptik.MOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment