Malware

Win32/Kryptik.PPT (file analysis)

Malware Removal

The Win32/Kryptik.PPT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.PPT virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.PPT?


File Info:

name: 409095223442EC52632A.mlw
path: /opt/CAPEv2/storage/binaries/448296d9afe1e25d6554bd0243445e4348d232e29ad30232070ba22faf553fe4
crc32: 5B66CECE
md5: 409095223442ec52632a388322b85563
sha1: 77331b4bd025f920866a5e07a965ddfe7aba72a5
sha256: 448296d9afe1e25d6554bd0243445e4348d232e29ad30232070ba22faf553fe4
sha512: 18ea8956ab228b2bb00f58c13b35aac7e1ae8861f44d4ce770b74a81718f22416b6ca4535591d433eacc7a7e1809ef04c72b2d4750fd685e7206985c48acd34f
ssdeep: 6144:WtID7knQo41QAOMwEIzUjQiZZvEYqWnKZ+pnVa5:WOh4BEIYjQWvrq1snk5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140749E2A7200CA78D81470F162A5DBC05EA63DFB1A052D477B74B245E5B60EBDFA20FD
sha3_384: 931e3e6808d8890f418f96e5d4516565d3b67728177863e2b155ed0618a5d41bc8da76737c0a2bf39a8aaf99058a67a3
ep_bytes: e8ab4e0000e916feffff8bc18b4c2404
timestamp: 2011-05-10 03:22:44

Version Info:

FileDescription: Microsoft
FileVersion: 1,0,0,0
InternalName: Application
LegalCopyright:
OriginalFilename: Example.exe
ProductName: Microsoft
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

Win32/Kryptik.PPT also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.lmue
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.IPZ.3
ClamAVWin.Malware.Agentb-6964357-0
FireEyeGeneric.mg.409095223442ec52
CAT-QuickHealWorm.Dorkbot.A
ALYacGen:Heur.IPZ.3
MalwarebytesGeneric.Malware.AI.DDS
SangforDropper.Win32.Wacatac.V4iz
K7AntiVirusTrojan ( 0024cd1a1 )
AlibabaVirTool:Win32/CeeInject.63f36ad5
K7GWTrojan ( 0024cd1a1 )
Cybereasonmalicious.23442e
BitDefenderThetaGen:NN.ZexaF.36250.vy1@aG3uC9ki
VirITTrojan.Win32.Generic.BRDC
CyrenW32/Kolab.I.gen!Eldorado
SymantecTrojan.Zbot
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.PPT
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.IPZ.3
NANO-AntivirusTrojan.Win32.MLW.dtiqj
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:Inject-AKN [Trj]
TencentMalware.Win32.Gencirc.10bee3ca
SophosMal/Kolab-G
BaiduWin32.Trojan.Kryptik.jd
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop3.29364
VIPREGen:Heur.IPZ.3
TrendMicroTROJ_GEN.R002C0CEU23
McAfee-GW-EditionPWS-FABL!409095223442
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.IPZ.3 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.IPZ.3
JiangminTrojanSpy.SpyEyes.cbz
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
XcitiumTrojWare.Win32.Kryptik.PPT@4eljpb
ArcabitTrojan.IPZ.3
ViRobotTrojan.Win.Z.Ipz.344095.RZ
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Worm/Win.AutoRun.R582241
McAfeePWS-FABL!409095223442
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CEU23
RisingTrojan.Generic@AI.100 (RDML:VvQiuvpr7VIlRNE1Qn6c5A)
YandexTrojan.GenAsa!ZA/63TP8oPY
Ikaruspossible-Threat.Crypt
FortinetW32/Wacatac.B!tr
AVGWin32:Inject-AKN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.PPT?

Win32/Kryptik.PPT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment