Malware

About “Win32/Kryptik.OEL” infection

Malware Removal

The Win32/Kryptik.OEL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.OEL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.OEL?


File Info:

name: B80C2ED9449AF04021C1.mlw
path: /opt/CAPEv2/storage/binaries/b337bda9bc67f8df5f06a20bfc3d996c2da8775d3f3014b79083f12cff75d577
crc32: 972E06EA
md5: b80c2ed9449af04021c195e1165c728e
sha1: 86499f5c859474fb572778ac580b52ccc5c010b0
sha256: b337bda9bc67f8df5f06a20bfc3d996c2da8775d3f3014b79083f12cff75d577
sha512: 61480064ead7346f81ca100e46d8cb14062f050ff1ad703e6fbc529e7aaa880e9874fbc8ac5fe2c66e49cfaa24da4191b80cbe16f656a5571f25b7e76f985579
ssdeep: 12288:xv/uYfiw+MlX6Ci5NodRxmxsERI+1v004vnoS:xv/uYawrX6znojIhc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAB423E7FB9BB983D921D3B0644F9539E8C4CF8D2699C47E6090853E18CF7A22563984
sha3_384: 8b52ad54472abdfa327a7178263c49d9fac07998a0cef565bde562b08f93a5ccb8651e469dcd38334a654e4dbf3e55ed
ep_bytes: 60be00c044008dbe0050fbffc78718f0
timestamp: 1970-01-01 18:37:43

Version Info:

CompanyName: BitDefender S.R.L.
FileDescription: BitDefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: UIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Win32/Kryptik.OEL also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.FKP.!c!.1
ClamAVWin.Trojan.Fakeav-33863
McAfeeFakeAV-SecurityTool.jq
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Heur.FKP.!c!.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00285f321 )
K7GWTrojan ( 00285f321 )
Cybereasonmalicious.9449af
VirITTrojan.Win32.Generic.BKOC
CyrenW32/FakeAlert.SU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.OEL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.!c!.1
NANO-AntivirusTrojan.Win32.ULPM.dbzvx
SUPERAntiSpywareTrojan.Agent/Gen-FraudLoad
AvastWin32:MalOb-GG [Cryp]
TencentMalware.Win32.Gencirc.10bee7f1
EmsisoftGen:Heur.FKP.!c!.1 (B)
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.Fakealert.21226
ZillyaTrojan.Kryptik.Win32.97133
TrendMicroTROJ_FAKEAV.SMWR
McAfee-GW-EditionFakeAV-SecurityTool.jq
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.b80c2ed9449af040
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.FKP.!c!.1
JiangminTrojan/Generic.qvfm
AviraTR/ATRAPS.Gen2
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Unknown
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.FKP.!c!.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R5355
BitDefenderThetaGen:NN.ZexaF.36250.EmKfaiMJjRcQ
ALYacGen:Heur.FKP.!c!.1
VBA32Trojan.ExpProc.014
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_FAKEAV.SMWR
RisingTrojan.Necurs!8.B03 (TFE:5:FtQTAh8SqVB)
YandexTrojan.GenAsa!QiX80Aot+1w
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Yakes.dwnc
FortinetW32/BrowHost.KP!tr
AVGWin32:MalOb-GG [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Kryptik.OEL?

Win32/Kryptik.OEL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment