Malware

Win32/Kryptik.POT (file analysis)

Malware Removal

The Win32/Kryptik.POT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.POT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.POT?


File Info:

name: 9A4AA74DD6EB0DF84558.mlw
path: /opt/CAPEv2/storage/binaries/752b61bc3a443847b7143a2b093624853d7c8ebacd5b8187cda4b0eb2c057541
crc32: DF2882E8
md5: 9a4aa74dd6eb0df84558d2483ea68ceb
sha1: f96cb1b84e1cd90abf012df316a44254aeae63f4
sha256: 752b61bc3a443847b7143a2b093624853d7c8ebacd5b8187cda4b0eb2c057541
sha512: 8eba1641bca18e9f573affe46c56b87a671e14b7353db56a2c24b42889532700748d5cb4a0fd203d420801872d4b131388eb34ded5afeb86d09c5c1e9531132b
ssdeep: 3072:ydS0osSGDD81T793f6bhi7Cza8G/ksAJjBicYr1q2b10SYP+nBoW9yX:8AJ11kJzuJAErBb1aUIX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17604F1395190E157E0F191B93867EA78731931FA8BD51CC53AA882FB2BA508F85173F2
sha3_384: 9427983e8a5c39e25129d5a957c0fb4e366af0b4b0fd8848b2cb9f24cbbe01e10e06bd0a7e2fd5818b5690531c0cd03e
ep_bytes: 558bec81eca40100006a006a006a006a
timestamp: 2005-09-20 01:14:33

Version Info:

FileVersion: 2.0.0.3
PrivateBuild: 1619
ProductVersion: 2.0.0.3
Translation: 0x0809 0x04b0

Win32/Kryptik.POT also known as:

BkavW32.AIDetectMalware
AVGWin32:Cybota [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Conjar.4
FireEyeGeneric.mg.9a4aa74dd6eb0df8
SkyhighBehavesLike.Win32.Generic.cc
McAfeeBackDoor-EXI.gen.k
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Kryptik.Win32.101249
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 003210941 )
AlibabaTrojan:Win32/Bulta.7859773a
K7GWBackdoor ( 003210941 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.3B02961514
VirITTrojan.Win32.Cryptor.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.POT
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Gbot-1441
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.4
NANO-AntivirusTrojan.Win32.Dwn.dmyge
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
AvastWin32:Cybota [Trj]
TencentWin32.Trojan.Generic.Nqil
SophosMal/FakeAV-IS
F-SecureBackdoor.BDS/Cycbot.BC
DrWebTrojan.DownLoader3.54243
VIPREGen:Heur.Conjar.4
TrendMicroBKDR_CYCBOT.SME3
EmsisoftGen:Heur.Conjar.4 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Repno.C@gen
JiangminBackdoor/Gbot.drt
VaristW32/Goolbot.J.gen!Eldorado
AviraBDS/Cycbot.BC
MAXmalware (ai score=100)
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Kryptik.QFB@40roaa
ArcabitTrojan.Conjar.4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Cycbot.B
GoogleDetected
AhnLab-V3Backdoor/Win32.Gbot.R7839
VBA32BScope.Trojan.Bedep
TACHYONBackdoor/W32.GBot.175616.AD
Cylanceunsafe
PandaTrj/Cycbot.gen
TrendMicro-HouseCallBKDR_CYCBOT.SME3
RisingTrojan.Win32.Fednu.fna (CLASSIC)
YandexTrojan.Cycbot.Gen!Pac.4
IkarusBackdoor.Win32.Cycbot
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Kryptik.POT!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Conjar

How to remove Win32/Kryptik.POT?

Win32/Kryptik.POT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment