Malware

Win32/Kryptik.RHB (file analysis)

Malware Removal

The Win32/Kryptik.RHB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.RHB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.RHB?


File Info:

name: 5B8F44B2D0F2D800381C.mlw
path: /opt/CAPEv2/storage/binaries/a6ea605eb37c252e7c084c37ab5ac309e29ddd28553c5cfafc34c80a032d3aee
crc32: 23FB411E
md5: 5b8f44b2d0f2d800381cd54fff64e93f
sha1: bfb07e84ed4ee4bd06c8f71b31cff8bef5787a0b
sha256: a6ea605eb37c252e7c084c37ab5ac309e29ddd28553c5cfafc34c80a032d3aee
sha512: 679364a1748f357059ba87b9bf13399836ca945da8efbce0b3d4f8b6d83537b905605e45da1c739189d642b1ba810b99815efadf408e2fccdfc9b30be298495b
ssdeep: 3072:LCUgOuXJbr+zHBD/rzBiC3C4H8h88FGQNMqloD/iKWYQ5Y5zDsl+:LZ6XJArBiCy7VF1mAYc+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1149DB39656B1B1C416AB393131B14D16073E308A9EDA16E304C43BEDB69F25E81BDB
sha3_384: 0e6fa2d0704a64fad7caba1878483c453bc8ad5ef0b5742bda59a933cb3cd8b131a3af5e8dce828c0be15e74762d87c3
ep_bytes: 830504e042000a730c031500e0420089
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Kryptik.RHB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Arto.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Renos.96
FireEyeGeneric.mg.5b8f44b2d0f2d800
CAT-QuickHealTrojan.Renos.PG
SkyhighBehavesLike.Win32.Dropper.cc
McAfeeDownloader-CEW.bj
MalwarebytesMalware.Heuristic.2090
ZillyaTrojan.Arto.Win32.23
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaTrojanDownloader:Win32/CodecPack.b0f075b2
K7GWTrojan ( 005485311 )
VirITTrojan.Win32.Arto.CEG
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.RHB
APEXMalicious
TrendMicro-HouseCallTROJ_ARTO.SMIA
AvastWin32:MalOb-GP [Cryp]
ClamAVWin.Downloader.112593-1
KasperskyTrojan-Downloader.Win32.CodecPack.sjt
BitDefenderGen:Variant.Renos.96
NANO-AntivirusTrojan.Win32.CodecPack.vpoki
TencentMalware.Win32.Gencirc.10b7018f
EmsisoftGen:Variant.Renos.96 (B)
F-SecureTrojan.TR/Renos.ptk
DrWebTrojan.DownLoader4.33327
VIPREGen:Variant.Renos.96
TrendMicroTROJ_ARTO.SMIA
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACB
IkarusTrojan-Downloader.Win32.Renos
JiangminTrojan/Arto.cg
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Renos.ptk
VaristW32/FakeAlert.NZ.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.CodecPack.sjt
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Renos.PG
XcitiumTrojWare.Win32.Kryptik.RLJ@466jo9
ArcabitTrojan.Renos.96
ZoneAlarmTrojan-Downloader.Win32.CodecPack.sjt
GDataGen:Variant.Renos.96
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R9861
BitDefenderThetaAI:Packer.6C314B6716
ALYacGen:Variant.Renos.96
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/Renos.gen
RisingDownloader.Renos!8.1D0 (TFE:2:v2iV3V0j7mR)
YandexTrojan.Arto!OAOaX62z/60
MAXmalware (ai score=100)
MaxSecureTrojan.CodecPack.Gen
FortinetW32/Delf.AT!tr
AVGWin32:MalOb-GP [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/CodecPack.sjt

How to remove Win32/Kryptik.RHB?

Win32/Kryptik.RHB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment