Malware

Win32/Kryptik.WIP (file analysis)

Malware Removal

The Win32/Kryptik.WIP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.WIP virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.WIP?


File Info:

name: B14E01A8999D3A8A71ED.mlw
path: /opt/CAPEv2/storage/binaries/b56d66df2b3fd825869f0dcdbfa00250e7b10db8d4e600c4f012f19d417a33da
crc32: E89AF38C
md5: b14e01a8999d3a8a71ed0abc52d0ca17
sha1: 56a14873958fcb43136d42744308d887464c7191
sha256: b56d66df2b3fd825869f0dcdbfa00250e7b10db8d4e600c4f012f19d417a33da
sha512: 3b3ff884291745c5d31a397282c42ceb972386a5d213a63c100e110cd3c3128e39942c0eff00b400a6b682c48fa16574aeb743117818990953ca7e9d3ec801a8
ssdeep: 6144:CYAAIjWa6P5TjPmeQlZTb4HQ2uNZSWhVfUBdT9BULzosaC:CYUjEP5TjPmeC1bquNQWHUBdTXUY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19384021A65C1AEFBF0D7CB348512A927495771E7AB52688F04CCE1840DF41B0EAF6F51
sha3_384: 2c2ce5d94ebfb72245a36bb47efaae5420997734456c9a98a2217bfd2c897f37e57010d0dfb93ed4fa8b44844305d6b6
ep_bytes: 60be009041008dbe0080feff57eb0b90
timestamp: 2011-11-11 15:10:18

Version Info:

Comments:
CompanyName:
FileDescription: exe
FileVersion: 1, 0, 0, 1
InternalName: exe
LegalCopyright: Copyright © 2011
LegalTrademarks:
OriginalFilename: exe.exe
PrivateBuild:
ProductName: exe
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Win32/Kryptik.WIP also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.Heur.xm0@!pd@ppgi
CAT-QuickHealTrojan.FakeAV
McAfeeArtemis!B14E01A8999D
VIPREGen:Trojan.Heur.xm0@!pd@ppgi
SangforTrojan.Win32.Save.a
Cybereasonmalicious.8999d3
CyrenW32/SuspPack.EE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.WIP
APEXMalicious
KasperskyVHO:Trojan-FakeAV.Win32.FakeRecovery.gen
BitDefenderGen:Trojan.Heur.xm0@!pd@ppgi
NANO-AntivirusTrojan.Win32.DownLoad2.hywks
AvastWin32:FakeAlert-BMU [Trj]
EmsisoftGen:Trojan.Heur.xm0@!pd@ppgi (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.DownLoad2.42876
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b14e01a8999d3a8a
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.xm0@!pd@ppgi
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[FakeAV]/Win32.FakeRecovery
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Heur.E4E2FD
ZoneAlarmVHO:Trojan-FakeAV.Win32.FakeRecovery.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R24328
BitDefenderThetaAI:Packer.D750FD401C
ALYacGen:Trojan.Heur.xm0@!pd@ppgi
VBA32BScope.Trojan.MTA
Cylanceunsafe
RisingTrojan.Kryptik!8.8 (TFE:1:lEMBob4vK8)
IkarusTrojan.Win32.FakeSysdef
MaxSecureVirus.W32.FakeAV.FakeRecovery.gen
FortinetW32/ULPM.2C75!tr
AVGWin32:FakeAlert-BMU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Kryptik.WIP?

Win32/Kryptik.WIP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment