Malware

Win32/Kryptik.ODU removal instruction

Malware Removal

The Win32/Kryptik.ODU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ODU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Win32/Kryptik.ODU?


File Info:

crc32: AB9A9C36
md5: 13733c3c7fc55c340a57ebd914abb559
name: 13733C3C7FC55C340A57EBD914ABB559.mlw
sha1: b9166c009c55357bc4d51ae9a3177f0694ad1240
sha256: d42cd8e7ed53090bf7808527f1f8306bbff7daa7c29addab64bb2d2e470a92da
sha512: 87bdda69063fe55c48e351ad56f57b2bf18131fcc653ebcf551f8c77ce977fb247a38031856c7cb92d327e61f109a24cbcee2771969e7c16fbe520ed6b4558c5
ssdeep: 12288:NuHdXrInRbM09MFlxFjr3Np7/ZqOVr21HoVhBtLHn/LiBPWHBnIbjg:mdXaRb/M/1V4KRGBPB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: UIScanner
FileVersion: 13,0,21,1
CompanyName: BitDefender S.R.L.
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
FileDescription: BitDefender Antivirus Scanner
OriginalFilename: uiscan.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.ODU also known as:

K7AntiVirusTrojan ( 0026d7d11 )
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.21226
CynetMalicious (score: 100)
ALYacGen:Heur.FKP.1
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.2626
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Obfuscator.3b8297b2
K7GWTrojan ( 0026d7d11 )
Cybereasonmalicious.c7fc55
CyrenW32/FakeAlert.SU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ODU
APEXMalicious
AvastWin32:Mystic
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.1
NANO-AntivirusTrojan.Win32.HmBlocker.falgsf
MicroWorld-eScanGen:Heur.FKP.1
TencentMalware.Win32.Gencirc.114bf8f2
Ad-AwareGen:Heur.FKP.1
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34738.Qq0@a0PqwniQ
VIPRETrojan.Win32.Ransom.do (v)
TrendMicroTROJ_FAKEAV.SMWR
McAfee-GW-EditionFakeAV-SecurityTool.js
FireEyeGeneric.mg.13733c3c7fc55c34
EmsisoftGen:Heur.FKP.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/HmBlocker.bhm
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.184AEA5
MicrosoftTrojan:Win32/Bulta!rfn
ArcabitTrojan.FKP.1
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Heur.FKP.1
AhnLab-V3Trojan/Win32.FakeAV.R5355
Acronissuspicious
McAfeeFakeAV-SecurityTool.js
MAXmalware (ai score=87)
VBA32Trojan.ExpProc.014
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.SMWR
RisingTrojan.Generic@ML.100 (RDML:Oicp6vZWxTObwqM3TDDeDQ)
YandexTrojan.GenAsa!smooncR4WIs
IkarusTrojan.Win32.Yakes
MaxSecureTrojan.Yakes.dwnc
FortinetW32/Yakes.S!tr
AVGWin32:Mystic
Paloaltogeneric.ml

How to remove Win32/Kryptik.ODU?

Win32/Kryptik.ODU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment