Malware

What is “Win32/Kryptik.RVB”?

Malware Removal

The Win32/Kryptik.RVB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.RVB virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.RVB?


File Info:

name: D53E6FACB0D48C8FB3F1.mlw
path: /opt/CAPEv2/storage/binaries/6d1c371d94854c77830da6dc55e4878a0a503e968d5373a6a323c67f4c967d7e
crc32: C95A5EC6
md5: d53e6facb0d48c8fb3f1e2c599a47bf9
sha1: 0be050f034eb947f1de4f91d3633a0feaadb3d88
sha256: 6d1c371d94854c77830da6dc55e4878a0a503e968d5373a6a323c67f4c967d7e
sha512: 0930985e1f3b0a21596a6cd10bf923047de92fb790ce209309e00d736e1459cb8ee83cb7df0a804e1c8521ae145f5e4c43c0bceef87c3d9576b26ee514f01a2a
ssdeep: 96:F2NMz9u2mWDHvn6Hyd8rHXAuHJU6peGwWF8k76SFh/JiF4PLWlDgwi:Po0mSd8rhpU6pVwRQ6SX/EF4KBi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109D11801B6E58536D8A94F3111924342ABBF6D2445B1610E0F6F5DA9BB73D278F2833A
sha3_384: d43844a937ab152511c661b24ef54c65f84a35f0e4b9ea3416d05d1ba0cb6bec57b89764ce2ccdcb3ce67320362036b4
ep_bytes: 6a00e84e050000a3fb354000e83e0500
timestamp: 2011-08-20 18:05:03

Version Info:

0: [No Data]

Win32/Kryptik.RVB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.lpXt
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d53e6facb0d48c8f
McAfeePWS-Zbot.gen.kr
AlibabaVirTool:Win32/Injector.51bcc23a
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.RVB
APEXMalicious
ClamAVWin.Trojan.6806876-1
AvastWin32:Kryptik-EJF [Trj]
TencentMalware.Win32.Gencirc.114951a0
ComodoMalware@#269940vijh9qz
ZillyaTrojan.Genome.Win32.130668
McAfee-GW-EditionPWS-Zbot.gen.kr
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACO
IkarusWorm.Win32.Rebhip
JiangminTrojanDownloader.Agent.dfne
WebrootW32.Malware.Gen
GoogleDetected
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.13
MicrosoftVirTool:Win32/Injector.gen!CF
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Agent.C124584
VBA32TrojanDownloader.Agent
RisingMalware.Undefined!8.C (TFE:4:rkf0GUlUmoD)
YandexTrojan.Injector!Me1M12IeWoQ
SentinelOneStatic AI – Suspicious PE
FortinetW32/Jorik.QF!tr
AVGWin32:Kryptik-EJF [Trj]
Cybereasonmalicious.034eb9
PandaGeneric Malware

How to remove Win32/Kryptik.RVB?

Win32/Kryptik.RVB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment